Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: router (5 articles)Clear

Chained MikroTik RouterOS SSH flaws let attackers seize exposed routers without authentication

CERT Polska detailed MikroTrick, a chain of two MikroTik RouterOS SSH vulnerabilities that together give attackers full administrative control of internet-exposed routers with no password, SSH key, or completed authentication. It combines an SSH state-machine flaw, CVE-2026-67279, with an argument-injection bug in the RouterOS login process, CVE-2026-86060. The state-machine flaw lets a client trigger an SSH key renegotiation during authentication, after which vulnerable RouterOS jumps straight to the command phase without confirming identity. Attack logs date to at least September 2, one day before MikroTik shipped patches in RouterOS 6.49.21, 7.23.4, and 7.24.2. CERT Polska had warned on September 5 of RouterOS flaws being exploited against public SSH services.

Check
Upgrade MikroTik RouterOS to 6.49.21, 7.23.4, or 7.24.2, remove SSH from public interfaces, and check exposed routers for signs of takeover.
Affected
Internet-exposed MikroTik routers on unpatched RouterOS let an unauthenticated attacker chain the two SSH flaws into full administrative control.
Fix
Patch RouterOS to the fixed releases, restrict SSH to management networks or disable it, and rotate credentials on any reachable device.

Unpatched Calix router flaw lets attackers expose devices behind home networks

An unpatched flaw in Calix residential routers used by several US broadband providers lets a remote, unauthenticated attacker create port-forwarding rules that expose devices on the local network to the internet. Tracked as CVE-2026-75501, the missing-authentication issue affects the Calix GS7 XGS model on a specific firmware version, and Calix supplies gear to large providers including Cox and Brightspeed. The researcher who found it reported it to the vendor in June, got no response, and disclosed through CERT/CC after further attempts failed. Because it lets an attacker punch holes through the router's network address translation, internal devices that were never meant to be reachable can be exposed. No fix is available.

Check
If you operate or manage affected Calix broadband routers, ask the provider or vendor about a fix and mitigations, and check devices for unexpected port-forwarding rules exposing internal systems.
Affected
Networks behind affected Calix GS7 XGS routers on the vulnerable firmware (CVE-2026-75501); a remote, unauthenticated attacker can add port-forwarding rules that expose internal devices to the internet, and no patch exists.
Fix
Press the broadband provider and Calix for a firmware fix, restrict remote management where possible, monitor for unauthorized port-forwarding entries, and place sensitive internal devices behind an additional firewall until resolved.

CISA adds actively exploited Cisco IOS flaw to its must-patch catalog

CISA has added a Cisco IOS vulnerability to its Known Exploited Vulnerabilities catalog after confirming it is being used in real attacks, requiring federal agencies to patch it under a binding deadline. Cisco IOS and IOS XE run the routers and switches behind many enterprise and service-provider networks, so a flaw here can give attackers a foothold deep in the network path. The listing lands amid heightened warnings, including a joint US-and-allies advisory this week urging better router hygiene against Russian state-sponsored targeting of network devices. Network gear is attractive because it often sits unmonitored, stays online for years, and rarely runs endpoint security; timely patching is the main defense.

Check
Identify Cisco IOS and IOS XE devices, check them against Cisco's advisory for the newly listed flaw, and prioritize patching internet-facing and edge devices while reviewing configurations and logs for tampering.
Affected
Organizations running affected Cisco IOS or IOS XE network devices, especially internet-facing routers and switches; active exploitation means unpatched devices are at real risk of compromise deep in the network path.
Fix
Apply Cisco's fixed software promptly, restrict and monitor management interfaces, follow current router-hygiene guidance against state-sponsored targeting, and inspect device configurations and logs for signs of unauthorized changes.

Tenda routers ship a hidden backdoor password with no patch available

CERT/CC has warned that several Tenda router firmware versions contain an undocumented authentication backdoor that grants full administrative access to the web management interface. Tracked as CVE-2026-11405, the flaw lives in the login function of the router's web server: if normal password checking fails, the firmware compares the supplied password against a hidden value stored in the device configuration and, on a match, grants admin access regardless of the username. It affects models including the FH1201, W15E, AC10, AC5, and AC6, is baked into the firmware, and cannot be disabled from the interface. Tenda has not responded, so there is no fix, and public exploit tooling is already scanning for vulnerable devices.

Check
Identify any Tenda routers in use, especially the affected FH1201, W15E, AC10, AC5, and AC6 models, and check whether the web management interface is reachable remotely or from untrusted networks.
Affected
Users of affected Tenda router models (CVE-2026-11405); anyone who can reach the web management interface can log in as administrator using a hidden backdoor password, with no valid credentials needed.
Fix
With no patch available, disable remote management, change the default LAN IP, restrict management access to trusted hosts, monitor for scanning on UDP port 7329, and plan to replace unsupported devices.

AryStinger botnet hijacks thousands of outdated D-Link routers as proxies

Researchers at XLab have documented a previously unknown botnet called AryStinger that has taken over more than 4,000 outdated routers, mostly D-Link DIR-850L and DIR-818LW models, and turned them into proxies for malicious traffic. It spreads by exploiting old, unpatched vulnerabilities and can scan networks, tunnel and proxy traffic, run commands, and tamper with DNS settings to hijack users' browsing. A more advanced Go-based variant targets NAS devices and adds internal network reconnaissance using open-source pentest tools. Infections cluster in South Korea and China but reach Sweden and Southeast Asia too. The compromised devices are end-of-life and will not receive fixes.

Check
Identify end-of-life D-Link routers and internet-exposed NAS devices on your networks, check for unexpected DNS settings, outbound proxy or tunneling traffic, and signs of remote command execution or scanning.
Affected
Outdated, end-of-life D-Link routers (notably DIR-850L and DIR-818LW) and exposed NAS devices running unpatched firmware; tampered DNS can silently hijack browsing for every device behind the router.
Fix
Replace end-of-life routers with supported models, update firmware on NAS devices, change default credentials, disable remote management and internet-exposed admin interfaces, and reset DNS settings to trusted resolvers.