Roskomnadzor Urges Operators to Inspect MikroTik Routers

The Main Radio Frequency Center (GRChTs), a subsidiary of Roskomnadzor, has issued an urgent directive to telecommunication operators. The directive recommends an immediate inspection of MikroTik routers deployed within their networks and advises operators to inform subscribers about the potential threat of hacking due to identified vulnerabilities in the RouterOS operating system.

Scale of Threat and Vulnerability Details

According to RBC, operators began receiving warning letters from the regulator on September 11. This initiative follows the discovery of six critical vulnerabilities in RouterOS by the CERT Polska team. These flaws impact key system components, including the SSH server and client, the bandwidth-test service, the X.509 certificate processing mechanism, and the WebFig interface.

Of particular concern is a chain of two vulnerabilities, dubbed MikroTrick. This exploit allows attackers to gain full control over a device without authentication, provided that remote SSH access is enabled on the router. Roskomnadzor estimates that approximately 100,000 such devices are in use across Russia, highlighting the potential scale of the threat. Hackers could intercept control over equipment, opening broad avenues for cybercrime.

Required Security Measures

Telecommunication operators are mandated not only to audit their equipment but also to implement appropriate measures to mitigate risks. This includes updating device firmware, disabling remote SSH access if not critically required, and informing end-users about the necessity of strengthening their home and office network security. Roskomnadzor’s recommendations aim to minimize the risks of data compromise and network infrastructure across the country.