Перейти к содержанию

MikroTik under the microscope: Roskomnadzor ordered measures due to the threat of hacking Latvian routers

GRCC instructed operators to update RouterOS and close external ports

The Main Radio Frequency Center (GRCC), subordinate to Roskomnadzor, instructed telecommunication operators to check Latvian MikroTik routers due to vulnerabilities in RouterOS. RBC writes about this, citing a letter from the center. This refers to devices installed for Russian subscribers.

Image source: Grok Imagine

About 100,000 such routers are used in Russia, according to Fplus. Vulnerabilities allow bypassing authentication, executing unauthorized commands, gaining access to files and confidential information, disrupting device operation, and establishing full control over them. MikroTik released RouterOS fixes in early September. Polish CERT Polska reported six vulnerabilities and recorded attacks on devices accessible from the internet.

The instruction does not mean a ban on equipment or its rejection — it is about checking and eliminating vulnerabilities. Before the update, operators are recommended to monitor potentially vulnerable routers and restrict access to settings via the internet through certain ports. Subscribers should check their RouterOS version and install the patch.

MikroTik is a Latvian manufacturer of network equipment, known for its flexible RouterOS operating system and affordable prices. The company has been operating since 1996, and its devices are used by providers, corporate clients, and home users to build networks of various scales. In Russia, MikroTik routers are popular among telecommunication operators and in the corporate segment.

Read more on the topic: