MikroTik has found a security vulnerability in RouterOS and releases containing a fix have been published in all channels.
This is an important security update. Most configurations are not at risk, but upgrading is highly recommended.
To give time to update your systems, we are not currently publishing detailed information.
Your device should already give you the option to upgrade software in the "Check for updates" menu.
Fix is included in:
- 7.25 beta 3
- 7.24.2
- 7.23.4
- 6.49.21
and newer.
For regular home device users and default configurations, the issue does not pose an immediate risk, but we still suggest all users to upgrade.
Steps after upgrade
RouterOS will check if your device has been compromised, and set it to "Flagged" status if it is. This will be written in the "Log" section. If your log has a critical entry saying your device has been Flagged, please follow the instructions in the Flagged status documentation page
Even if your device is not in Flagged state, after upgrading your RouterOS, inspect your device configuration for any unknown scripts, users or other config you do not recognise. This is suggested in any case, Flagged or not. Flagged status does not delete configuration, you should still inspect it.
This article will be updated with more information in due time.



