Roskomnadzor Urges Operators to Inspect MikroTik Routers
The Main Radio Frequency Center (GRChTs), a subsidiary of Roskomnadzor, has issued an urgent directive to telecommunication operators. The directive recommends an immediate inspection of MikroTik routers deployed within their networks and advises operators to inform subscribers about the potential threat of hacking due to identified vulnerabilities in the RouterOS operating system.
Scale of Threat and Vulnerability Details
According to RBC, operators began receiving warning letters from the regulator on September 11. This initiative follows the discovery of six critical vulnerabilities in RouterOS by the CERT Polska team. These flaws impact key system components, including the SSH server and client, the bandwidth-test service, the X.509 certificate processing mechanism, and the WebFig interface.
Of particular concern is a chain of two vulnerabilities, dubbed MikroTrick. This exploit allows attackers to gain full control over a device without authentication, provided that remote SSH access is enabled on the router. Roskomnadzor estimates that approximately 100,000 such devices are in use across Russia, highlighting the potential scale of the threat. Hackers could intercept control over equipment, opening broad avenues for cybercrime.
Required Security Measures
Telecommunication operators are mandated not only to audit their equipment but also to implement appropriate measures to mitigate risks. This includes updating device firmware, disabling remote SSH access if not critically required, and informing end-users about the necessity of strengthening their home and office network security. Roskomnadzor’s recommendations aim to minimize the risks of data compromise and network infrastructure across the country.
This is quite concerning, especially the MikroTrick vulnerability allowing full control without authentication. I’m curious, how quickly can operators typically roll out firmware updates across such a large number of devices? And what’s the typical timeline for end-users to actually implement these security recommendations on their own routers? It feels like there’s a significant window of vulnerability even after the warnings go out.