SECURITY·중요도 9·2026. 09. 23.·The Hacker News

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

── KO ──────────────────

MikroTrick 체인을 통해 공격자가 MikroTik 라우터를 무단으로 장악할 수 있는 취약점이 발견되었습니다.

MikroTik RouterOS의 두 가지 SSH 취약점이 결합되어 공격자가 비밀번호나 SSH 키 없이 인터넷에 노출된 라우터의 전체 관리 권한을 가질 수 있습니다. CERT Polska는 이 체인을 MikroTrick이라고 명명했습니다. 체인은 SSH 상태 머신 결함(CVE-2026-67279)과 RouterOS 로그인 프로세스의 인수 주입 버그(CVE-2026-86060)를 결합합니다. 이 두 취약점은 중요한 보안 위험을 수반합니다.


── EN ──────────────────

The MikroTrick chain allows attackers to take over MikroTik routers without a password or SSH key.

Two SSH vulnerabilities in MikroTik RouterOS have been combined to allow attackers complete administrative control over internet-exposed routers without needing a password or SSH key. This vulnerability chain, referred to as MikroTrick by CERT Polska, includes an SSH state-machine flaw (CVE-2026-67279) and an argument-injection bug in the RouterOS login process (CVE-2026-86060). These flaws pose a significant security risk.

원문 보기 →목록으로