# Pre-auth RCE on MikroTik: exploited before the patch, rebuilt in three hours

> Source: <https://tolmo.com/blog/mikrotrick-agentic-detection/>
> Published: 2026-09-06 08:00:00+00:00

## In short

- MikroTrick chains two RouterOS bugs into a full, unauthenticated takeover of
any MikroTik device with SSH reachable. Exploitation ran from September 2,
**one day before the patches and three days before the advisory** .
- We reproduced the entire chain end to end from only the public advisory and
the patch diff, in a single uninterrupted run: **approximately three hours and
roughly 110,000 tokens** (the token count covers the main session; the
subagent that reverse-engineered the patched binaries in the background ran
on top of that), verified
against both vulnerable releases. Four frontier models given the same inputs
failed.
- **These devices no longer sit only at the edge.** They wire up local AI
clusters (the DGX Spark, TP>2 crowd), so one compromise exposes model
weights, datasets, and all east-west traffic.
- **Defense still investigates at ticket speed while offense iterates at agent
speed** , and CERT Polska cannot rule out additional undisclosed bugs. The
detection section and IoC table below are the checks to run now.

On September 5, [CERT Polska
disclosed](https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/)
six vulnerabilities in MikroTik RouterOS.
Two of them chain into **MikroTrick**: a full, unauthenticated takeover of any
router with SSH reachable. Attackers had been using it since at least
September 2, a day before MikroTik shipped fixes and pushed a
notification to every phone running its app, begging people to update.
