All articles
5. 4. 2018
2 min read

IT specialist advises – check routers!

IT specialists love them for their wide range of configuration options, customers especially for their price and low running costs. Routers of the well-known Latvian manufacturer Mikrotik with the RouterOS operating system based on Linux are very popular in general and also among our customers.

Unfortunately, bugs occur in almost every software (and hardware) and a good manufacturer usually fixes them regularly, which is another reason for the popularity of the mentioned platform. Some Mikrotik Routers have been in service for 10 years or more and still the manufacturer releases regular updates for them. On the other hand, the manufacturer does not force the user to install updates, and by default the routers are not even updated automatically, because it is assumed that someone on the owner’s side will handle regular updates so that it does not compromise operations.

If you think that competing vendors have it better handled, try to remember the situation in 2015 when a botnet abusing the Ubiquiti manufacturer’s equipment took down the wireless network of one of the providers in the Czech Republic and caused a very challenging crisis situation.

Last year, a critical security flaw was found in RouterOS 6.38 and lower, allowing a potential attacker to remotely take full control of the router. All that is needed is – a web interface accessible from the Internet or management using Winbox. Attackers primarily exploit this flaw for coordinated overlay attacks on websites, but under certain circumstances it is possible to attack any website, including, for example, internet banking.

Because our clients’ security is our top priority, we update their network infrastructure automatically. And if you are not our client, have your router checked. Our survey of 100 random routers available from the Internet shows that more than 50% of them are vulnerable.

Jan Mitoraj, Head of Outsourcing at Railsformers s.r.o.

Have a project?

Get in touch and we'll discuss how we can help.
Contact us

More articles

1 Aug 2026

Cyber Resilience Act: New Rules for Secure Software and Digital Products

The European Union is introducing another important regulation in the field of cybersecurity. It is called the Cyber Resilience Act, or CRA for short, and applies to all products with a digital component. This means not only smart devices, but also software, applications, and systems that connect to a network or communicate with another service…
Read the article
15 Jul 2026

Withdrawal button – Wontilles responds in advance to new legislative requirements

The legislative environment in the field of e-commerce is undergoing constant changes, which place high demands on online shop operators.
Read the article
1 Jun 2026

Railsformers at the Faculty of Arts at the OU: Ruby on Rails in practice and now also in IT business

At the Faculty of Science of the University of Ostrava, we have long been giving students practical experience with Ruby on Rails development and showing them what it looks like to work on real web applications. From the original pilot course, we have developed a stable course Ruby on Rails I and II, which we…
Read the article