MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels.
This is an important security update. Most configurations are not at risk, but upgrading is highly recommended.
To give time to update your systems, we are not currently publishing detailed information.
Your device should already give you the option to upgrade software in the “Check for updates” menu.
Fix is included in:
For regular home device users the issue does not pose an immediate risk, but we still suggest all users to upgrade.
RouterOS will check if your device has been compromised, and set it to “Flagged” status if it is. This will be written in the “Log” section. If your log has a critical entry saying your device has been Flagged, please follow the instructions in the Flagged status documentation page.
Even if your device is not in Flagged state, after upgrading your RouterOS, inspect your device configuration for any unknown scripts, users or other config you do not recognise.
This article will be updated with more information in due time.
Contact us about vulnerabilities