Vietnam.vn - Nền tảng quảng bá Việt Nam

Tens of thousands of MikroTik routers in Vietnam are at risk of being turned into botnets

Báo Sài Gòn Giải phóngBáo Sài Gòn Giải phóng27/07/2023


SGGPO

Worldwide , the number of MikroTik routers exposed to the Internet that are at risk of being exploited via HTTP and Winbox are 500,000 and 900,000 devices, respectively. This number in Vietnam is 9,500 via HTTP and 23,000 via Winbox, according to Bkav's records.

In Vietnam, the number of MikroTik devices connecting to the Internet as of July 26 is in the tens of thousands.
In Vietnam, the number of MikroTik devices connecting to the Internet as of July 26 is in the tens of thousands.

A serious vulnerability has just been discovered in the MikroTik RouterOS operating system, allowing an authenticated attacker to escalate privileges from Admin to Super Admin to execute arbitrary code, take full control of devices and turn them into botnets, and launch DDoS attacks.

The newly discovered vulnerability has the identifier CVE-2023-30799, CVSS severity score 9.1. However, Bkav experts believe that the "deadly point" here is the "default password". "To exploit the vulnerability CVE-2023-30799, hackers need to gain Admin rights while most of the default passwords on the devices have not been changed," said Mr. Nguyen Van Cuong, Director of Network Security at Bkav.

MikroTik routers are popular products from the Latvian networking equipment manufacturer. They run on the proprietary MikroTik RouterOS operating system, allowing users to access the administration page via either the HTTP web interface or the Winbox application to create, configure and manage a LAN or WAN.

With such a large number of devices connecting to the Internet, to minimize risks, Bkav recommends that users immediately update to the latest patch (6.49.8 or 7.x) for RouterOS, and implement the following additional solutions: Disconnect the Internet on the administration interfaces to prevent remote access; set a strong password if the administration page must be published; turn off the Winbox administration program and use the SSH protocol instead, because MikroTik only provides protection solutions for the SSH interface...



Source

Comment (0)

No data
No data
Admire the million-year-old Chu Dang Ya volcano in Gia Lai
It took Vo Ha Tram 6 weeks to complete the music project praising the Fatherland.
Hanoi coffee shop is bright with red flags and yellow stars to celebrate the 80th anniversary of National Day September 2nd
Wings flying on the A80 training ground
Special pilots in the flying formation to celebrate National Day September 2
Soldiers march through the hot sun on the training ground
Watch helicopters rehearse in the sky of Hanoi in preparation for National Day September 2
U23 Vietnam radiantly brought home the Southeast Asian U23 Championship trophy
Northern islands are like 'rough gems', cheap seafood, 10 minutes by boat from the mainland
The powerful formation of 5 SU-30MK2 fighters prepares for the A80 ceremony

Heritage

Figure

Business

No videos available

News

Political System

Local

Product