Before an upgrade:
- Remember to make backup/export files before an upgrade and save them on another storage device;
- Make sure the device will not lose power during upgrade process;
- Device has enough free storage space for all RouterOS packages to be downloaded.
What's new in 7.25rc1 (2026-10-01):
- bgp - show interface names and VRF names in BGP logs;
- bridge - fix MLAG bond slave interfaces not coming up when the MLAG configuration is removed (introduced in v7.25beta3);
- bridge - fix MLAG peer ports going down when a bridge port is enabled (introduced in v7.25beta5);
- bridge - fix virtual slave ports being removed from the bridge when MLO is triggered (introduced in v7.25beta4);
- bth - add default client DNS and allowed IPs settings (additional fixes);
- dhcpv6-server - fix send-reconfigure for DHCPv6 clients behind a relay;
- ipv6 - fix missing IPv6 link-local addresses on some interfaces when the device is busy during boot;
- lcd - improve stability when an SFP reports an unknown link speed;
- switch - add packet and byte counters for ACL rules on Marvell Prestera switches (additional fixes);
- switch - fix ACL rules remaining in the switch TCAM after removal (introduced in v7.25beta3);
- system - improve stability;
- vlan - add a forced-mac-address option for VLAN interfaces (additional fixes);
- webfig - fix comboboxes in the System/PTP section not being editable (introduced in v7.25beta3);
- webfig - fix empty Bridge and Interface/Ethernet sections (introduced in v7.25beta4);
Other changes since 7.24.5:
- app - add the networkRouterIP variable for container apps;
- app - allow the privileged mode to be enabled per service in the container app YAML;
- app - fix CHR apps getting stuck on "starting" on slower boards;
- app - show an error when an app variable cannot be resolved;
- app - update the environment variables of the docker-with-komodo app;
- bgp - add the always-compare-med setting;
- bgp - fix BGP unnumbered connections within a VRF;
- bgp - include the VNI number in outgoing EVPN routes;
- bgp - log failed BGP connection attempts;
- bridge - add dynamic ARP inspection;
- bridge - add IP source guard;
- bridge - add mlag-lacp-fallback and mlag-init-delay settings for MLAG;
- bridge - fix a false "already added as bridge port" error;
- bridge - fix an MLAG peer getting stuck in the disabled state after config changes;
- bridge - fix bridge ports not forwarding;
- bridge - fix MLAG MAC handling when used with VRRP;
- bridge - fix VRRP MAC behavior in MLAG setups;
- bridge - improve FDB synchronization between MLAG peers when VLANs are added;
- bridge - make MVRP work with MLAG dual bonds;
- bridge - rename the IGMP last-member-interval property to last-member-query-interval;
- bridge - warn about VLAN entries when vlan-filtering is disabled;
- bth - add resumable file uploads;
- bth - check the available disk space before a file upload;
- bth - fix file share issues when enabled through WinBox files menu;
- bth - fix the file share getting stuck when disabling;
- bth - return upload errors in JSON format;
- capsman - add hw-protection-threshold;
- capsman - fix the last-ip value being shown backwards;
- certificate - fix ACME certificate issuance for wildcard domains;
- certificate - refactor certificate internal processes;
- console - allow the array access operator to accept arrays of indices or keys;
- console - expose globals in the API;
- console - fix background ":execute as-string" jobs not terminating on interrupt;
- console - fix comment wrapping in the monitor command;
- console - fix inconsistent /ip/firewall/filter print with src-address-list and dst-address-list;
- console - fix the where filter ignoring flags set to false;
- console - improve export order;
- console - prevent an out-of-memory condition when ":execute as-string" produces large output;
- console - prevent duplicate entries in /port/remote-access;
- container - add a Ctrl-] escape sequence to exit a stuck container shell;
- container - fix container interface handling on CHR;
- container - fix veth interface left running after restarting a stopped container;
- container - require the container device-mode to enable swap;
- crypto - fix a possible crash during IPsec processing on Qualcomm devices;
- detnet - use a single random source port;
- dhcpv4-client - ignore forcerenew packets that are not unicasted to client;
- dhcpv4-server - add ipv6-only-preferred parameter to respect option 108;
- dhcpv4-server - show DHCP option 82 parameters in ASCII in addition to hex;
- dhcpv6-client - add option 39 with the client hostname;
- dhcpv6-client - fix DHCPv6 client address handling after prefix-hint changes;
- dhcpv6-client - remove a duplicate dhcp-options parameter;
- dhcpv6-relay - use the packet's source MAC for option 79 if relay and client are on the same link layer;
- dhcpv6-server - add option 39 (FQDN) support and add-dns-entries option;
- disk - improve RAID5/6 throughput;
- dns - fix resolving domain names that end with a dot;
- dot1x - rename the reauth-timeout to reauth-period;
- email - fix server certificate verification;
- email - show certificate related errors in the log;
- ethernet - add the arp-accept parameter for interfaces with MAC;
- ethernet - fix a stability issue on RB1100AHx2 under heavy traffic;
- ethernet - fix bogus fast-path Rx traffic reported on an unconnected ether8 port on RB5009;
- ethernet - fix link flap and unexpected reboots on RB5009;
- ethernet - fix PPPoE link flapping on Intel X710;
- ethernet - fix PPPoE over VLAN not working on Mellanox ConnectX-4;
- ethernet - fix SFP compatibility on hAP ax S and hEX S (2025) devices;
- ethernet - improve stability on x86 routers with Mellanox NICs;
- evpn - publish MAC-IP routes (RT-2) for neighbors;
- fetch - improve upload state reporting when using sftp;
- fetch - never set a cookie jar for HTTP requests;
- fetch - show a clearer error when keep-result and output are both used;
- firewall - add NAT-related fields to CEF format logging;
- hardware - show the device name and location in /system/resource/hardware menu;
- igmp-proxy - improve stability when changing /routing/igmp-proxy parameters;
- iot - add a GPIO menu in WinBox;
- iot - add Bluetooth output power control;
- iot - allow a custom radio plan even under a regional lock;
- iot - enforce the fixed antenna gain on boards with an embedded antenna;
- iot - fix round-trip-time timing issues in LoRaWAN Basic Station;
- ip-service - fix services becoming unreachable after their VRF is disabled and re-enabled;
- ipsec - add XFRM interface support;
- ipsec - fix IKEv1 tunnels failing to establish when the commit bit is set;
- ipsec - fix policy and SA handling after moving it to netlink;
- ipv6 - fix a failure when releasing DHCPv6 prefix delegation pools;
- ipv6 - fix cases when address is lost after reboot if prefix was taken from pool;
- ipv6 - fix the DNS timer in router advertisements;
- ipv6 - ignore router advertisements received on interfaces not in the accepting list;
- l3hw - fix IPv6 link-local traffic being routed incorrectly;
- l3hw - improve stability of L3 hardware offload when using IPv4-mapped IPv6 addresses;
- l3hw - optimize ECMP nexthop offloading;
- leds - add dark-mode support for L41;
- leds - fix missing LED triggers when an R11e card is installed;
- lte - accept both y and yes for eSIM confirmation;
- lte - add band display support for Huawei ME909s modems;
- lte - add missing network error messages for MBIM modems;
- lte - add the sms-protocol=qmi option for sending and reading SMS;
- lte - do not force reconfiguration on roaming network when roaming is disabled;
- lte - fix LTE interfaces disappearing after FOTA updates;
- lte - fix missing new firmware update notification on some modems;
- lte - fix multi-APN connections not passing traffic on AT modems;
- lte - fix the subscriber number not updating after switching SIM slots;
- lte - improve system stability when using Quectel EP06-E MBIM modem;
- lte - improve system stability with eSIM-capable MBIM modems;
- lte - remove leftover APN slave interfaces when the master LTE interface is removed;
- lte - use also the network reported ipv6 MTU on MBIM interfaces when "auto" mtu option used;
- lte - use RA for IPv6 acquisition for FG621;
- netinstall - add branding-and-custom-packages parameter for custom NPK packages;
- netinstall - fix a duplicate device entry on RB2011 with SFP;
- netinstall - fix adding and exporting server comments;
- netinstall - fix multiple active interfaces inheriting the first interface's settings;
- netinstall - fix Netinstall failing to reinstall RB850Gx2 devices;
- netinstall - fix Netinstaller's memory check failing downloads to disk;
- ospf - fix DR/BDR traffic not being received with multiple instances;
- ospf - improve stability when a neighbor is lost;
- pim - add MLD support for PIM;
- pim - fix duplicate PIM configuration parameters;
- pim - fix PIM-SM issues with IPv6;
- pim - fix wrong or missing PIM configuration by separating PIM and GMP per interface;
- poe-out - add port-type field to poe monitor and print output;
- poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
- poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
- poe-out - fix PoE fault led behavior;
- poe-out - fix PoE ports entering overload state when a PSU is fed from a UPS;
- port - accumulate incoming data in log file even without TCP clients connected;
- port - add an FTDI latency_timer option for low-latency serial applications;
- ppp - add port interface info to PPP outbound channel defaults;
- ppp - fix a packet leak during dial-on-demand connection of a ppp-out interface;
- ppp - fix BG77 modem port name and channel count;
- ppp - fix the offline firmware-update notification for BG77/BG770 modems;
- ppp - fix the SINR value reported for BG77 and BG770 modems;
- ptp - add support for fixed master and slave port roles;
- ptp - add transparent clock mode;
- ptp - fix dropped packets on bridges with IGMP snooping and add vlan-id port setting;
- qos - fix PFC and lossless buffer issues (introduced in v7.23);
- queue - fix a typo in the cake-overhead-scheme parameter value;
- sfp - fix QSFP28 optical modules failing to establish a link on CCR2216 and CRS520;
- sfp - improve QSFP-DD link establishing to NVIDIA DGX Spark and other devices;
- sniffer - improve packet time resolution;
- sniffer - show packet timestamps with nanosecond precision in WinBox;
- snmp - add an OID and logging for blacklisted program access;
- snmp - add CAPsMAN radio data to SNMP;
- snmp - add dynamic SNMP engine ID assignment;
- snmp - add interface table with mtu and l2mtu OIDs;
- snmp - add IP pool OIDs;
- snmp - add IPv6 address and interface name to the MNDP neighbour table;
- snmp - add OID blacklisting;
- snmp - add OIDs for Netwatch probes;
- snmp - add OSPF MIB tables;
- snmp - add SHA-2 authentication for SNMPv3;
- snmp - add transmit drop counters;
- snmp - add VRRP status OIDs for monitoring;
- snmp - fix the reported capability flags in LLDP-MIB;
- snmp - fix the snmp tools timing out when authentication is used;
- snmp - log a warning when the src-address family does not match the request;
- snmp - remove an interface OID that should not be accessible;
- ssh - add a connection id to SSH log entries;
- ssh - add host key verification for the SSH client;
- ssh - limit server output to the client's window size;
- ssh - show router host key fingerprint;
- ssh - switch the default host key type to Ed25519;
- ssh - warn users when weak RSA key is being used;
- ssl - enabled hardware accelerated GCM on Alpine CPUs;
- ssl - improve logging;
- switch - fix degraded slow-path throughput on CRS304 switch (introduced in v7.22);
- system - fix the frequency units from Mhz to MHz;
- system - improve stability (includes CVE-2026-31431, CVE-2026-67280);
- system - reboot automatically when the boot process fails to start;
- system - reduce the fan control interval on multi-core boards;
- system - remove the channel label from the RouterOS version;
- system - show health settings and overtemp options based on device capabilities;
- system - warn about a missing wifi driver package on BE boards;
- tftp - add VRF support;
- traffic-flow - fix a kernel failure when disabling traffic flow on a busy system;
- user - fix removal of inactive REST API sessions (introduced in 7.21);
- userman - improve stability when importing database files;
- vlan - warn when a VLAN interface is created on a slave interface;
- webfig - add a generic table and union group support;
- webfig - add column resizing to embedded tables;
- webfig - hide the left menu only on QuickSet and Terminal pages;
- webfig - improve comboboxes to select the first matching option while typing;
- webfig - update style;
- webfig - update the login page Help link;
- wifi - add a stream-port argument to configure the sniffer streaming server port;
- wifi - add fast transition support for MLD devices;
- wifi - add interworking, aaa and steering settings to the network configuration;
- wifi - add more steering debug logs;
- wifi - add network 'labels' parameter to WinBox and WebFig;
- wifi - do not preserve branding package on cap when upgrading via capsman;
- wifi - fix CAPsMAN failing when mangle marking is used with encrypted data channels;
- wifi - fix channel reselect interval/time operation for wifi-qcom-be and wifi-mediatek interfaces;
- wifi - fix incorrect scan results for 320 MHz access points;
- wifi - fix MLD link type change and SA query in station mode;
- wifi - fix per-link client statistics for MLO connections;
- wifi - fix SAE authentication using a wrong cached PMK;
- wifi - fix station statistics not updating after switching MLD links;
- wifi - fix the interworking network type;
- wifi - fix the wrong band shown in the registration table;
- wifi - fix traffic processing on CAPsMAN after an interface is disabled;
- wifi - perform a channel switch instead of dropping clients on radar detection;
- wifi - preserve dude package on cap when upgrading via capsman;
- wifi - report channel in log messages;
- wifi - report management frame protection (MFP) usage in registration-table;
- wifi - show the EAP user identity in the registration table;
- wifi - show the MLD links and SSID in MLO client log messages;
- wifi-mediatek - fix 4.9 GHz band operation on the A42;
- wifi-mediatek - fix the 5 GHz access point failing to start after reconfiguration on the A42;
- wifi-mediatek - improve MLO client reconnection;
- wifi-qcom - fix disconnects during fast transition roaming;
- wifi-qcom - fix station mode association failures;
- wifi-qcom - improve IP multicast delivery to wireless clients;
- wifi-qcom-ac - fix a regression in station MAC address handling;
- wifi-qcom-ac - reduce package size;
- wifi-qcom-be - add hw-protection-mode support;
- wifi-qcom-be - add the distance setting for 802.11be devices;
- wifi-qcom-be - fix the block ack request being declined after a channel switch;
- wifi-qcom-be - fix Wi-Fi intermittently unavailable after reboot;
- wifi-qcom-be - improve throughput in dense client environments;
- winbox - add a filtered LLDP tab to neighbor discovery;
- winbox - add a Security tab and reorganize bridge and port dialogs;
- winbox - add a wifi radio regulatory info (reg-info) view;
- winbox - add device-mode configuration;
- winbox - add ISIS support;
- winbox - add progress bar support to the GUI;
- winbox - add RSRP and RSRQ signal graphs to the PPP info view;
- winbox - add the client MTU option for WireGuard peers;
- winbox - add the container save option;
- winbox - add wifi Spectral Scan support;
- winbox - allow power-cycling multiple interfaces at once;
- winbox - allow tuple fields with more than two values and multiple separators;
- winbox - fix SFP optical power values of 0.0 dBm not being shown;
- winbox - fix the channel.reselect-interval range field in CAPsMAN;
- winbox - fix the EC/IO signal quality graph;
- winbox - fix the ISIS neighbor level type being empty for "l2";
- winbox - fix the Memory Limit field of fq_codel to use bytes;
- winbox - fix the Min Prefix field in the routing rule dialog;
- winbox - fix the MPLS TE tunnel path hops field;
- winbox - fix the range field displayed in route filters;
- winbox - fix the signal indication graphs for ppp-out interfaces;
- winbox - fix the Skins menu for user groups opening a non-existent window;
- winbox - fix the system note display on startup;
- winbox - fix the wifi Authentication Types and Encryption fields;
- winbox - fix wg-import creating an WireGuard interface without a config file;
- winbox - improve status reporting under Tools/Email menu;
- winbox - make the Power Cycle button act only on the selected interface;
- winbox - open the Format Drive panel only for supported disks;
- winbox - remove the redundant empty status field from the License window;
- winbox - rename "send" to "transmit" in the Bandwidth Test window;
- winbox - rework the switch QoS statistics table;
- winbox - show WireGuard peer information;
- wireguard - add the client-mtu parameter;
- wireguard - allow referencing a peer by its name;
- wireguard - allow unsetting the client-listen-port;
- wireguard - improve error message reporting when adding a new peer;
- wireguard - keep peer rx/tx counters when the peer is disabled and enabled;
- wireguard - support comment lines in wg-import configuration files;
- wireguard - treat empty private-key and preshared-key values as none;
- wireguard - use the MTU value when importing a configuration;
- wireguard - warn when an allowed-address overlaps another peer;
- www - add the remote client IP and domain to HTTPS log messages;
- www - fix a memory leak when parsing authentication headers;
- www - improve URI parsing;
To upgrade, click Check For Updates under System/Packages menu and select the testing Channel in RouterOS configuration interface, or head to our download page: http://www.mikrotik.com/download
- Everything went smoothly
- I encountered an issue after the update (please post about the device, configuration, and unexpected symptoms)
- I encountered an issue, but solved it (please post the solution)
If you experience version related issues, then please send supout file from your router to support@mikrotik.com. The file must be generated while a router is not working as suspected or after some problem has appeared on the device
Please keep this forum topic strictly related to this particular RouterOS release.