This is hardly any exploit. The article describes how to create a fake router, and somebody using Winbox can connect to this fake router, and make problems for this somebodys Windows computer.
So in short, don’t connect with Winbox to unknown machines, and to protect your own, don’t disable the default firewall on the public port. Make sure you disable the “admin” user and make your own user.
If connecting to a remote router then anybody upstream could divert traffic intended for an actual router to such a fake router so this is a perfectly valid concern.
Winbox is terrible from a security point of view!If you have to use it remotely then use it over an established VPN connection.
True, but hopefully the other applications might show some signs that something is not right - e.g. invalid certs. Winbox has some particular vulnerabilities in that regard which are a serious concern when one considers that Winbox is downloading DLLs.