cd /news/ai-infrastructure/pre-auth-rce-on-mikrotik-exploited-b… · home › topics › ai-infrastructure › article
[ARTICLE · art-141385] src=tolmo.com ↗ pub= topic=ai-infrastructure verified=true sentiment=↓ negative

Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours

CERT Polska disclosed six MikroTik RouterOS vulnerabilities on September 5, two of which chain into "MikroTrick," a full unauthenticated takeover of any router with SSH reachable, with exploitation observed since at least September 2 — one day before MikroTik shipped fixes and three days before the advisory. The researchers reproduced the entire chain end to end from only the public advisory and the patch diff in roughly three hours and about 110,000 tokens, verified against both vulnerable releases, while four frontier models given the same inputs failed. CERT Polska said it cannot rule out additional undisclosed bugs, and the report notes these devices now wire up local AI clusters such as the DGX Spark, so one compromise exposes model weights, datasets, and all east-west traffic.

read1 min views3 publishedSep 6, 2026

In short #

  • MikroTrick chains two RouterOS bugs into a full, unauthenticated takeover of any MikroTik device with SSH reachable. Exploitation ran from September 2, one day before the patches and three days before the advisory .
  • We reproduced the entire chain end to end from only the public advisory and the patch diff, in a single uninterrupted run: approximately three hours and roughly 110,000 tokens (the token count covers the main session; the subagent that reverse-engineered the patched binaries in the background ran on top of that), verified against both vulnerable releases. Four frontier models given the same inputs failed.
  • These devices no longer sit only at the edge. They wire up local AI clusters (the DGX Spark, TP>2 crowd), so one compromise exposes model weights, datasets, and all east-west traffic.
  • Defense still investigates at ticket speed while offense iterates at agent speed , and CERT Polska cannot rule out additional undisclosed bugs. The detection section and IoC table below are the checks to run now.

On September 5, CERT Polska disclosed six vulnerabilities in MikroTik RouterOS. Two of them chain into MikroTrick: a full, unauthenticated takeover of any router with SSH reachable. Attackers had been using it since at least September 2, a day before MikroTik shipped fixes and pushed a notification to every phone running its app, begging people to update.

── more in #ai-infrastructure 4 stories · sorted by recency
── more on @mikrotik 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/pre-auth-rce-on-mikr…] indexed:0 read:1min 2026-09-06 · —