MIKROTIK has released security updates for RouterOS after identifying a severe flaw that prompted a rapid patch across all channels. The company’s advisory confirms that the underlying issue affects multiple software iterations released over several years and that the critical fix is now included in RouterOS versions 7.24.2, 7.23.4, 6.49.21, and 7.25 beta 3.
While MikroTik notes that devices with default home configurations are less at immediate risk, authorities and security experts nevertheless urge all users to upgrade promptly to mitigate potential exploitation.
The report from Latvia’s CERT[.]LV notes an uptick in attacks targeting MikroTik routers worldwide, though it stops short of tying the activity to a specific intrusion technique. A number of administrators have observed an unfamiliar ‘ops’ account with full administrative privileges on a sizeable portion of their devices, with some cases showing a disabled version of that account after updating.
MikroTik has not officially classed the ‘ops’ user as a definitive breach indicator, leaving some uncertainty around its significance in exploitation. Post-update, RouterOS will actively scan for signs of intrusion, logging a “Flagged” status that restricts several dangerous administrative functions, but experts warn that this does not by itself remove unauthorised configurations or malicious scripts.
Recommended actions focus on thorough post-update auditing: review system logs and the active user list, inspect all scripts and configuration parameters, remove unfamiliar items, and reset credentials. MikroTik further advises blocking internet access to WinBox, WebFig, and SSH, tightening administrative ports behind a firewall, and isolating management operations within a dedicated VLAN accessed securely via VPN.