Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical ASUS Control Center Bug Lets Attackers Gain Admin Access
September 6, 2026
Critical RCE Flaw in Adobe Commerce, Magento Under Active Attack
September 6, 2026
Critical MikroTik RouterOS CVE-2023-30799 exploited for network takeover
September 6, 2026
Home/CyberSecurity News/Critical MikroTik RouterOS CVE-2023-30799 exploited for network takeover
CyberSecurity News

Critical MikroTik RouterOS CVE-2023-30799 exploited for network takeover

Key Takeaways Attackers are actively exploiting CVE-2023-30799, an unauthenticated remote access vulnerability in MikroTik RouterOS. The flaw grants unauthenticated attackers direct shell access via...

Emy Elsamnoudy
Emy Elsamnoudy
September 6, 2026 3 Min Read
2 0

Key Takeaways

  • Attackers are actively exploiting CVE-2023-30799, an unauthenticated remote access vulnerability in MikroTik RouterOS.
  • The flaw grants unauthenticated attackers direct shell access via SSH, even without credentials.
  • All RouterOS versions are affected, with patches available across stable, long-term, and beta channels (7.25 beta 3, 7.24.2 stable, 7.23.4 long-term, and 6.49.21 long-term).
  • A new built-in detection mechanism in patched versions flags suspicious configurations, but manual auditing is still critical.

MikroTik RouterOS Vulnerability Under Active Exploitation

Network administrators globally are grappling with active exploitation of a critical unauthenticated remote access vulnerability, CVE-2023-30799, within MikroTik RouterOS. The flaw allows attackers to gain full network control, necessitating immediate patching of affected devices.

Table Of Content

  • Key Takeaways
  • MikroTik RouterOS Vulnerability Under Active Exploitation
  • Technical Details and Exploitation
  • Real-World Compromise Reports
  • Post-Patch Detection and Mitigation
  • What You Should Do

MikroTik confirmed the severe security issue on September 3, 2026, announcing that fixes had been released across all major RouterOS channels. These include versions 7.25 beta 3, 7.24.2 stable, 7.23.4 long-term, and 6.49.21 long-term.

Initially, MikroTik withheld specific technical details of the vulnerability to provide administrators a crucial window to update their systems before attackers could reverse-engineer the flaw. Despite this precaution, exploitation began almost immediately, with security researchers and forum users independently uncovering the attack vectors.

Technical Details and Exploitation

Discussions on the official MikroTik support forum revealed that the vulnerability resides within a core library shared by various RouterOS services. This means any exposed service leveraging this codebase could serve as an entry point for attackers.

A forum contributor who reverse-engineered the issue confirmed it is tied to SSH. This flaw permits any unauthenticated remote attacker to gain direct shell access to the device, regardless of whether the router is configured for password or SSH key-based authentication. Consequently, any MikroTik router with an SSH service accessible from the internet or an untrusted network remains vulnerable until patched, requiring no prior credential compromise or user interaction.

Latvia’s national CERT issued an alert, corroborating a significant rise in attacks targeting MikroTik routers. The agency urged both organizational and individual users to update to the newly released patched builds, reinforcing MikroTik’s guidance that fixes are available for both the 7.x stable and legacy long-term branches.

Real-World Compromise Reports

Evidence of active exploitation quickly emerged within the MikroTik user community. An administrator reported on Reddit an incident on September 2, 2026, around 08:00 UTC. An unauthorized user account named “ops” was created by another rogue account labeled “0,” which was granted write and policy permissions. The intrusion was traced to an SSH connection originating from the IP address 82.192.72.4.

While the administrator noted that the rogue account primarily appeared to be used for logins, with no obvious malicious scripts immediately visible, the team suspected a deeper compromise that RouterOS’s internal tools might not detect. This led to the conclusion that a full netinstall was necessary to guarantee the devices were clean.

Post-Patch Detection and Mitigation

RouterOS now includes a built-in detection mechanism designed to flag such unauthorized tampering. After upgrading, the operating system automatically scans the entire configuration upon startup. If signs of unauthorized changes are found, the device is set to “Flagged” status, and a critical entry is logged in the system log.

Devices in a flagged state face operational restrictions, including the inability to enable new scheduler entries, SOCKS proxy, PPTP, L2TP, IPsec, proxy, and SMB configurations, until an administrator manually audits and clears the state. MikroTik’s guidance is clear: if a device is flagged, assume compromise, thoroughly audit all configurations, rotate all passwords, and then clear the flagged status.

Even routers that do not show a flagged status should not be presumed safe. Both MikroTik and independent researchers advise manually reviewing configurations for any unrecognized users, scripts, or scheduled tasks after updating, as some compromise artifacts may not trigger the automated detection.

What You Should Do

  • Immediately Update RouterOS: Prioritize upgrading all MikroTik devices to the latest patched versions: 7.25 beta 3, 7.24.2 stable, 7.23.4 long-term, or 6.49.21 long-term, or newer.
  • Audit All Devices: Regardless of whether a device shows a “Flagged” status, conduct a comprehensive manual audit of all configurations, users, scripts, and scheduled tasks for any unauthorized changes.
  • Rotate Credentials: Change all administrative passwords and SSH keys on affected devices.
  • Restrict Remote Management: Limit SSH and other management interfaces from public internet access. If remote access is necessary, restrict it to trusted management networks and enforce key-based authentication.
  • Perform Netinstall if Compromised: If a device is confirmed compromised, consider a full netinstall to ensure complete removal of any persistent malware or unauthorized configurations.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

AI Agents Steal Root Credentials in Under 10 Hours

Next Post

Critical RCE Flaw in Adobe Commerce, Magento Under Active Attack

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
New Windows Backdoors Controlled via Popular Messaging Services
September 5, 2026
Invisible Unicode Characters Evade Phishing Detection in Millions of Emails
September 4, 2026
Hackers Exploit AI Models Claude, Qwen, DeepSeek for Cyberattacks
September 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us