Urgent.News

What's breaking now, across thousands of outlets.

Tech

How Many MikroTik Devices Are Actually Reachable From the Internet?

How Many MikroTik Devices Are Actually Reachable From the Internet? When CERT Polska disclosed the MikroTrick chain in MikroTik RouterOS on September 5, 2026, the practical question for defenders was not whether the flaw was serious. It was how much of the internet's RouterOS population is exposed to it. The exploit requires the SSH management service to be reachable from the internet, so…

The MikroTrick vulnerability chain in MikroTik RouterOS, disclosed by CERT Polska on September 5, 2026, has raised concerns about the extent of Internet access to affected devices. To assess exposure, a September 19, 2026 ZoomEye data analysis was conducted, yielding valuable insights into the scale of the issue. The findings reveal that 31,069,202 devices were identified as MikroTik, 2,855,574 as RouterOS, and 937,854 specifically as MikroTik RouterOS.

When focusing on port 8291, the Winbox management port, the count further narrows to 8,913,154. These numbers indicate the widespread presence of MikroTik devices on the Internet, but they lack version information and confirmations of SSH accessibility. While ZoomEye's index captures devices identified as RouterOS, it does not specifically pinpoint vulnerable versions or confirm whether SSH is reachable.

It is crucial to remember that exposure does not equate to compromise. The 122,000 affected devices reported by public sources are estimates of exposed and potentially vulnerable instances, not confirmed intrusions. To gain a clearer understanding of the risk within your own network, it is recommended to verify directly which devices have SSH accessible from the Internet.

ZoomEye can assist in identifying assets within your address space, but direct verification is essential. Restricting SSH, WebFig, and the bandwidth-test service to a trusted management network can effectively eliminate the attack precondition. Regularly checking logs for unauthorized SSH logins and monitoring for unauthorized configuration changes are also crucial steps in maintaining the security of RouterOS devices.

It is important to note that the exposure data presented here is based on ZoomEye's September 19, 2026 query, and may not reflect the current status of devices. The article emphasizes that these figures represent population measurements and not definitive vulnerability or compromise determinations.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Saturday 19 September →