Tendvane

← All articles

NetworkSeptember 6, 2026

MikroTik shipped a fix and refused to say what for. It didn't help.

MikroTik's advisory on 3 September was unusually terse. Fixes in 6.49.21, 7.23.4, 7.24.2 and 7.25 beta 3, upgrading highly recommended, and this line: "To give time to update your systems, we are not currently publishing detailed information." Withholding the specifics is a defensible call. It buys a few days before somebody compares the old code with the new.

It bought less than that. CERT Polska has since described a two-flaw combination it calls MikroTrick, in which an attacker who can reach a router's SSH service over the internet gets full administrative control without any password at all. Successful attacks go back to at least 2 September. Everything from RouterOS 6.0.0 up to 6.49.20, and 7.0.0 through 7.24.1, is in scope.

MikroTik's own note says home devices running the default firewall rules block outside access to the management ports, so a box that was set up and left alone is probably not exposed. Default is doing a lot of work in that sentence. These routers turn up in small offices, in flats where the landlord's contractor configured the internet, and in setups where somebody opened SSH years ago to fix something from work and never closed it. Updating takes a minute through System, then Packages, then Check For Updates. While you're in there, look at whether SSH and the web interface are reachable from outside and switch them off if they are. After updating, MikroTik suggests checking the log for a "Flagged" status and scanning the configuration for user accounts or scripts you did not create.

Most people genuinely don't know what their router is. Tendvane's Network scan lists every device currently on your home network, which is the quickest way to find out what make and model is sitting in the hallway.

Sources

Download Tendvane