Over 300,000 MikroTik Devices Found Vulnerable to Remote Hacking Bugs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-14847 | Directory Traversal in MikroTik RouterOS Winbox Interface (Unauthenticated File Read) CVE-2018-14847 is a directory traversal (CWE-22) vulnerability in the Winbox interface of MikroTik RouterOS through version 6.42. An unauthenticated remote attacker can send crafted Winbox requests that traverse directories to read arbitrary files on the device, while authenticated attackers can also write arbitrary files. By reading files an attacker can retrieve sensitive device data such as stored credentials or configuration, and file write capability can support further compromise of the router. Any MikroTik router or device running RouterOS at or below 6.42 with the Winbox interface reachable is affected, which includes large numbers of internet-exposed edge and ISP devices. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-12-01), has multiple public PoCs, and compromised MikroTik routers have been used by threats such as Trickbot (as C2 proxies) and the Mēris botnet, with public scans reporting over 300,000 vulnerable devices. Do: Apply MikroTik's updates per vendor instructions, moving RouterOS above version 6.42, prioritizing devices with Winbox reachable from untrusted networks. Until patched, restrict or disable Winbox access from WAN/untrusted interfaces to limit unauthenticated file reads. Given known botnet abuse of this flaw, check devices for signs of compromise and rotate credentials that may have been exposed via file reads. | 9.1 | 96% | KEV PoC ×7 |
| mass≈300,000+ internet-exposed MikroTik devices | |
| CVE-2018-7445 | Pre-Authentication Stack Buffer Overflow RCE in MikroTik RouterOS SMB CVE-2018-7445 is a stack-based buffer overflow (CWE-119) in the SMB service of MikroTik RouterOS that occurs while processing NetBIOS session request messages. An attacker triggers it simply by sending a crafted NetBIOS session request to the device's SMB service; because the overflow occurs before authentication, no credentials or user interaction are required. Successful exploitation yields unauthenticated remote code execution on the router, giving the attacker a foothold on the device itself and a potential pivot point into the networks it serves. All MikroTik devices on all architectures running RouterOS before 6.41.3 (stable branch) or 6.42rc27 (release-candidate branch) are affected wherever the SMB service is reachable. Exploitation is confirmed: public proof-of-concept code has existed since March 2018 (Core Security advisory, Exploit-DB 44290), EPSS assigns a ~61% 30-day exploitation probability, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-09-08, indicating in-the-wild use (ransomware use unknown). Do: Upgrade all MikroTik devices to RouterOS 6.41.3 or later on the stable branch (or 6.42rc27 or later on the release-candidate branch), per the CISA KEV required action. Until patched, disable the SMB service where it is not needed or firewall-restrict SMB ports so only trusted hosts can reach it. Audit RouterOS versions across your fleet, prioritizing internet-facing routers given confirmed in-the-wild exploitation. | 9.8 | 61% | KEV PoC ×3 |
| mass≈300,000+ internet-exposed MikroTik devices (2018 public scans and reporting counted over 300,000 vulnerable MikroTik devices) | |
| CVE-2019-3978 +1 in the same advisory: …3977 | RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoning NVD description · AI analysis pending | 7.5 | 10% |
| — | ||
| CVE-2021-36260 | Unauthenticated Command Injection in Hikvision Device Web Server CVE-2021-36260 is a command injection flaw (CWE-78) in the web server embedded in a wide range of Hikvision security camera and related devices, caused by insufficient input validation. An attacker triggers it by sending a crafted HTTP request to the device's web management interface, allowing commands to be executed on the device without authentication. Successful exploitation grants unauthenticated remote code execution on the camera or recorder, letting an attacker take control of the device, pivot into the surrounding network, or use the devices as a botnet platform. Any Hikvision device running the affected web server firmware is at risk, which includes cameras, recorders, and other surveillance hardware deployed in homes, businesses, and government facilities. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10 and carries a 99.9% EPSS probability of exploitation within 30 days, while no public proof-of-concept code is cataloged in the provided data and no CVSS score has been issued yet. Do: Apply firmware updates issued by Hikvision per the vendor's instructions, as required by CISA's KEV listing for this vulnerability. Restrict the device web management interface to trusted networks or VPN access and avoid direct internet exposure. Review web server logs for anomalous HTTP requests to the device interface and signs of command execution, and prioritize internet-facing devices for patching first. | 9.8 | 100% | KEV PoC ×3 |
| massmillions of installed devices, with roughly hundreds of thousands to over a million Hikvision web interfaces exposed to the internet | |
| CVE-2021-41653 | The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted paylo The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field. NVD description · AI analysis pending | 9.8 | 76% | PoC |
| — |
Full article747 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 09, 2021
At least 300,000 IP addresses associated with MikroTik devices have been found vulnerable to multiple remotely exploitable security vulnerabilities that have since been patched by the popular supplier of routers and wireless ISP devices.
The most affected devices are located in China, Brazil, Russia, Italy, Indonesia, with the U.S. coming in at number eight, cybersecurity firm Eclypsium said in a report shared with The Hacker News.
"These devices are both powerful, [and] often highly vulnerable," the researchers noted. "This has made MikroTik devices a favorite among threat actors who have commandeered the devices for everything from DDoS attacks, command-and-control (aka 'C2'), traffic tunneling, and more."
MikroTik devices are an enticing target not least because there are more than two million of them deployed worldwide, posing a huge attack surface that can be leveraged by threat actors to mount an array of intrusions.
Indeed, earlier this September, reports emerged of a new botnet named Mēris that staged a record-breaking distributed denial-of-service (DDoS) attack against Russian internet company Yandex by using network devices from Mikrotik as an attack vector by exploiting a now-addressed security vulnerability in the operating system (CVE-2018-14847).
This is not the first time MikroTik routers have been weaponized in real world attacks. In 2018, cybersecurity firm Trustwave discovered at least three massive malware campaigns exploiting hundreds of thousands of unpatched MikroTik routers to secretly install cryptocurrency miners on computers connected to them. The same year, China's Netlab 360 reported that thousands of vulnerable MikroTik routers had been surreptitiously corralled into a botnet by leveraging CVE-2018-14847 to eavesdrop on network traffic.
CVE-2018-14847 is also among the four unaddressed vulnerabilities discovered over the last three years and which could enable full takeover of MikroTik devices -
- CVE-2019-3977 (CVSS score: 7.5) - MikroTik RouterOS insufficient validation of upgrade package's origin, allowing a reset of all usernames and passwords
- CVE-2019-3978 (CVSS score: 7.5) - MikroTik RouterOS insufficient protections of a critical resource, leading to cache poisoning
- CVE-2018-14847 (CVSS score: 9.1) - MikroTik RouterOS directory traversal vulnerability in the WinBox interface
- CVE-2018-7445 (CVSS score: 9.8) - MikroTik RouterOS SMB buffer overflow vulnerability
In addition, Eclypsium researchers said they found 20,000 exposed MikroTik devices that injected cryptocurrency mining scripts into web pages that users visited.
"The ability for compromised routers to inject malicious content, tunnel, copy, or reroute traffic can be used in a variety of highly damaging ways," the researchers said. "DNS poisoning could redirect a remote worker's connection to a malicious website or introduce a machine-the-middle."
"An attacker could use well-known techniques and tools to potentially capture sensitive information such as stealing MFA credentials from a remote user using SMS over WiFi. As with previous attacks, enterprise traffic could be tunneled to another location or malicious content injected into valid traffic," the researchers added.
MikroTik routers are far from the only devices to have been co-opted into a botnet. Researchers from Fortinet this week disclosed how the Moobot botnet is leveraging a known remote code execution (RCE) vulnerability in Hikvision video surveillance products (CVE-2021-36260) to grow its network, and use the compromised devices to launch distributed denial-of-service (DDoS) attacks.
In a separate report, the enterprise cybersecurity firm said that the operators of a botnet known as Manga aka Dark Mirai are actively abusing a recently disclosed post-authenticated remote code execution vulnerability (CVE-2021-41653) to hijack TP-Link routers and co-opt the appliances to their network of infected devices.
Update
In a statement shared with The Hacker News, the Latvian company said that "there are no new vulnerabilities in RouterOS," while stressing that keeping the operating system up to date is an "essential step to avoid all kinds of vulnerabilities."
"Unfortunately, closing the old vulnerability does not immediately protect the affected routers. We don't have an illegal backdoor to change the user's password and check their firewall or configuration. These steps must be done by the users themselves," the company explained.
"We try our best to reach out to all users of RouterOS and remind them to do software upgrades, use secure passwords, check their firewall to restrict remote access to unfamiliar parties, and look for unusual scripts. Unfortunately, many users have never been in contact with MikroTik and are not actively monitoring their devices. We cooperate with various institutions worldwide to look for other solutions as well."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/12/over-300000-mikrotik-devices-found.html