Summary: CERT Polska is observing active attacks against MikroTik RouterOS. A chain of two vulnerabilities can provide full device takeover without prior authentication when SSH is reachable from untrusted networks. Around 122,500 MikroTik routers are reachable over SSH according to Shadowserver scans cited by Golem, but that number is not the same as the number of vulnerable or compromised devices.
For administrators, the immediate message is simple: update, restrict external SSH and inspect the device for changes afterwards. The wider mosaic is more interesting: the vulnerabilities were discovered with assistance from OpenAI models, details were initially meant to stay private, and attackers still reconstructed parts of the fixes by comparing patched versions. AI-accelerated research, patch management and reverse engineering are now colliding directly.
Confirmed
CERT Polska coordinated disclosure of six RouterOS vulnerabilities. Two can be combined into the attack chain named “MikroTrick”. According to the CERT, the chain can lead to complete router takeover without prior authentication when SSH is publicly reachable.
CERT Polska says it has observed the combination in real attacks and confirms that the released patches stop the attacks it has seen. MikroTik lists fixes in 7.25beta3, 7.24.2, 7.23.4 and 6.49.21, as well as newer releases. The vendor also notes that default home configurations do not normally expose SSH directly to the internet.
After an update, RouterOS checks for known traces of compromise and may mark the device as “Flagged”. That is useful, but not a clean bill of health: both MikroTik and CERT Polska explicitly warn that the absence of a Flagged status does not prove that the router is uncompromised.
The 122,500-router figure needs context
Golem's September 7 headline says that “over 100,000 routers are exposed to ongoing attacks”. Its article is more precise than the headline. Shadowserver scans cited by Golem show roughly 122,500 MikroTik routers worldwide with SSH reachable from the internet, including about 1,700 in Germany.
That measurement describes potential attack surface, not a confirmed victim count. Golem correctly states in the body that the scans cannot show how many of those systems are actually vulnerable and still unpatched. The report therefore holds up technically in substance; the headline simply pushes the exposure figure further toward “ongoing attacks” than the scan data alone can prove.
The defensible wording is narrower: MikroTrick is under active exploitation, and roughly 122,500 MikroTik routers expose the service that makes the observed chain relevant. The overlap between public SSH exposure, a vulnerable version and an actual attack is currently unknown.
The mosaic: AI speeds discovery while attackers analyse patches too
CERT Polska provides an unusually transparent description of its research process. The team used GPT-5.5-cyber and GPT-5.6-sol through an OpenAI programme to develop hypotheses, compare binary versions and systematically test protocol states. The researchers also stress that every hypothesis was verified on real RouterOS systems, checked with negative controls and assessed by humans.
This is not evidence that an AI agent autonomously “hacked” RouterOS. It is, however, a credible example of models accelerating vulnerability research when they are combined with a controlled laboratory, tooling and human validation.
The other side of the timeline is just as important. CERT Polska initially wanted to withhold technical details to give administrators time to patch. Once patched RouterOS packages were public, however, researchers or attackers could compare the binaries and reconstruct parts of the vulnerabilities. Active exploitation forced the CERT to accelerate disclosure.
That shrinks the traditional patching window. Defenders receive the fix, but attackers simultaneously receive a binary diff showing where the vendor changed code. AI tools can make that analysis faster on both sides.
An update is not enough after a possible compromise
RouterOS administrators should first move to a fixed or newer release. For the long-term channel, 7.23.5 is now newer than the original security release 7.23.4. MikroTik's changelog lists 7.23.5 from September 4; the rapid follow-up matters because an IPv6/DHCPv6 regression was reported after 7.23.4.
SSH should then be removed from direct internet exposure or at least restricted to trusted source addresses. MikroTik recommends using a VPN such as WireGuard for management access instead of exposing management ports. Administrators should inspect unknown users, scripts, scheduler tasks, proxies, tunnels and other configuration changes.
For a confirmed compromise, CERT Polska recommends rebuilding from a trusted state, rotating passwords, keys and other secrets, and explicitly avoiding a blind restore of a full backup taken from the potentially compromised device.
What argues against the broader alarm
The public attack surface should not be confused with a mass compromise of every exposed device. Default configurations block external SSH, and updated systems are protected against the chain observed by CERT Polska. Not all of the 122,500 reachable routers are necessarily running a vulnerable version.
The AI role should not be exaggerated either. CERT Polska explicitly describes a controlled laboratory and extensive human verification. The models accelerated analysis and hypothesis generation; they did not replace the security researchers.
Pandorex Analysis
For administrators, MikroTrick is fundamentally an exposure problem with severe consequences. A management service that is unnecessarily reachable from the internet turns a critical vulnerability into an immediate remote-takeover risk. Patching is mandatory, but the stronger architectural decision is to keep management interfaces off the public internet in the first place.
Pandorex assessment: Active exploitation is confirmed and the technical urgency is high. The widely quoted figure of 122,500 routers, however, describes SSH-visible attack surface, not 122,500 systems proven to be vulnerable or compromised.