Critical MikroTik RouterOS Flaw Allows Remote Takeover Without Login
A serious vulnerability has been identified in MikroTik RouterOS, the operating system used on many routers deployed worldwide, including in Australia. The flaw, rated 9.8 out of 10 in severity, exists in the web management service and can be triggered by a single crafted request sent over the network, with no login required.
Successful exploitation could let an attacker take full control of the router as an administrator, or force it offline through a denial of service. Because routers sit at the edge of business networks, a compromised device could expose internal systems, intercept traffic, or be used as a launchpad for further attacks.
MikroTik has released a fix. Businesses running affected RouterOS versions (before 7.24) should update to version 7.23 or later immediately using the official MikroTik download site.