Bug Report: Hotspot Captive Portal Crash on Malformed HTTP Request (v7.19.3)

This can be considered a security issue (Denial-of-Service from unauthenticated user in public facing, untrusted environment), so follow this MikroTik Routers and Wireless - Security to report the issue to MikroTik (send email to security@mikrotik.com).

See @normis' reply related to an on-going vulnerability:

Also, upgrade to the latest stable version first (7.19.6) and retest your finding before filling the report.