Jump to content

Patch Now: Up to 900K MikroTik Routers Vulnerable to Total Takeover


Recommended Posts

Quote

Up to 900,00 MikroTik routers — a popular target for threat actors including nation-state groups — may be open to attack via a privilege escalation vulnerability in the RouterOS operating system.

The vulnerability (CVE-2023-30788) gives attackers a way to take complete control of affected MIPS-processor-based MikroTik devices and pivot into an organization's network, according to researchers from VulnCheck, which just published several new exploits for the flaw. Attackers can also use it to enable man-in-the-middle attacks on network traffic flowing through the router, they warned. Versions of MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to the issue.

"The worst-case scenario is that an attacker can install and execute arbitrary tools on the underlying Linux operating system," says Jacob Baines, leader researcher at VulnCheck. "Remote and authenticated attackers can use the vulnerability to get a root shell on the router," by escalating admin-level privileges to that of a super-administrator.

MikroTik has released a fix for impacted RouterOS versions, and admins should apply it quickly.

https://www.darkreading.com/vulnerabilities-threats/up-to-900k-mikrotik-routers-vulnerable-total-takeover

Edited by itman
Link to comment
Share on other sites

  • Most Valued Members

4 years before I had a client with Mikrotek , one of the worst experiences I had with a router/firewall..

Link to comment
Share on other sites

Most of our network is based on Mikrotik products. No worse or better than other systems.

As of this vulnerability, it's exploitable only if malicious person has administrative access to device, so, this is the main problem. Here is what Mikrotik says about it

https://blog.mikrotik.com/security/cve-2023-30799.html

Edited by karlisi
Link to comment
Share on other sites

  • Most Valued Members
Posted (edited)
29 minutes ago, karlisi said:

Most of our network is based on Mikrotik products. No worse or better than other systems.

As of this vulnerability, it's exploitable only if malicious person has administrative access to device, so, this is the main problem. Here is what Mikrotik says about it

https://blog.mikrotik.com/security/cve-2023-30799.html

Indeed it's just my opinion , many will disagree with me , and true vulnerabilities happen to all , but I just found other brands easier to work with.

Edited by Nightowl
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...