Language Settings
Select Website Language

GDPR Compliance

We use cookies to ensure you get the best experience on our website. By continuing to use our site, you accept our use of cookies, Privacy Policy, and Terms of Service.

CERT-In Warns of MikroTik RouterOS SSH Vulnerability

1 hour ago

3

0

CERT-In warns of a MikroTik RouterOS SSH flaw. The vendor says CVE-2026-67279 has been exploited in the wild and lists fixed versions

By News National Editorial Team

NEW DELHI, October 12, 2026: India's cybersecurity agency has warned network administrators about a vulnerability in MikroTik RouterOS that could allow an unauthenticated remote attacker to bypass the expected Secure Shell (SSH) login process and perform unauthorised operations on affected devices.

CERT-In published Vulnerability Note CIVN-2026-0494 on October 9, identifying the flaw as CVE-2026-67279. The agency said exploitation could allow unauthorised operations involving files managed by RouterOS, including files containing configuration and diagnostic information. MikroTik's own security notice says this SSH vulnerability has been exploited in the wild.

What the flaw allows

SSH is commonly used by administrators to manage routers and other network devices remotely. The vulnerability involves the handling of authentication and rekeying in the SSH implementation of affected RouterOS versions.

CERT-In said an attacker who can reach the SSH service could potentially open a session channel and send an execution request without completing the expected authentication workflow. The resulting access could permit file creation, modification or reconstruction within the RouterOS-managed file namespace.

The warning does not mean every MikroTik router is vulnerable. Exposure depends on the installed software version and whether the affected management service is reachable by an attacker.

Which versions are affected?

CERT-In lists the following affected ranges:

  • RouterOS 6.0.0 to versions earlier than 6.49.21.

  • RouterOS 7.0.0 to versions earlier than 7.23.4.

  • RouterOS 7.24 to versions earlier than 7.24.2.

MikroTik identifies fixed versions for this vulnerability as 6.49.21, 7.23.4 and 7.24.2, or later releases containing the relevant fix. Administrators should consult the vendor's current security guidance before updating, particularly because the vendor has also documented other RouterOS vulnerabilities with separate patch requirements.

Why network administrators should act

Routers often sit at the boundary between internal systems and the public internet. They may connect offices, servers, remote workers and cloud services. A compromised device could therefore expose configuration details or provide an attacker with a foothold for further activity.

Small businesses, educational institutions, internet service providers and enterprises should identify all RouterOS devices in their networks. Devices that have not been updated may remain vulnerable even if they appear to be operating normally.

CERT-In's notice establishes that the vulnerability exists. MikroTik's statement about exploitation in the wild adds urgency, but it does not establish that a particular Indian organisation has been attacked through this flaw.

Recommended security steps

Administrators should check the installed RouterOS version and apply the appropriate vendor security update. They should restrict SSH access to trusted management networks and disable remote administration where it is not required.

Organisations should also review logs for unexpected login attempts, new files, unexplained configuration changes and suspicious outbound traffic. Strong unique credentials, multi-factor authentication where supported, network segmentation and tested backups provide additional protection.

If compromise is suspected, teams should preserve logs and configuration snapshots, rotate potentially exposed credentials and follow their incident-response procedures.

A wider lesson for infrastructure security

Network devices are sometimes overlooked in patching programmes because they are viewed as stable infrastructure rather than active computing systems. The MikroTik advisory shows why routers require the same disciplined inventory, monitoring and update processes applied to servers and endpoints.

Organisations should use official advisories to prioritise remediation and verify that patches have actually been installed. For affected MikroTik users, checking the version and applying the vendor's fix are immediate practical steps.

Sources:

Click here to Read More
Previous Article
CERT-In Warns of Cyberattacks Targeting India's Payment APIs
Next Article
South Korea and Japan Investigate Cyberattacks Amid AI Security Concerns

Related Cyber Security Updates:

Are you sure? You want to delete this comment..! Remove Cancel

Comments (0)

    Leave a comment