Hackers exploit a chain of recently disclosed MikroTik RouterOS vulnerabilities to hijack MikroTik devices. CERT Polska says the combination can give an attacker full control of a device without authentication when the device’s SSH service is reachable from the internet. The CERT described the exploit chain as “MikroTrick,” and reported it after coordinating disclosure with MikroTik.
The outlets agree that the issue involves two vulnerabilities working together rather than a single flaw alone. Both reports link successful exploitation to network exposure of SSH, which provides the entry point for the attack chain. The reports also note that CERT Polska identified six RouterOS vulnerabilities overall and coordinated their disclosure with MikroTik, while the two that form the key combination enable takeover without authentication under the stated conditions.
Across coverage, emphasis varies between describing the underlying research and presenting the practical impact. Help Net Security highlights the “MikroTrick” chain and the specific authentication bypass condition, while Bleeping Computer focuses on the broader picture of new RouterOS flaws and router hijacking through SSH exposed to the internet. Both characterize the activity as an exploit chain targeting MikroTik routers running affected RouterOS versions.