See the youtube presentation as mentioned in here. (The whole Vault7 thread might also interest you)
http://forum.mikrotik.com/t/statement-on-vault-7-document-release/106907/1
If you don’t have time to watch:
- There was no authorisation needed for the exploit (no username/password needed)
- Netinstall is the only way to remove exploits
- Start with the default firewall, which is blocking access from interfaces in the WAN interface list.
…as a beginning …