Do you see traffic targeting tcp port 5678 at any time or only when winbox is running on your PC? Could be winbox neighbour detection as those packets originate PC or so you claim…
Hard to say as I am using winbox log to view LOL…
I can peak at wireshark when and compare,
sandbox lan, cable internet - hex1
sandbox lan, cable internet -hex2
real homelan behind zyxel 40USW
And see if there is any appreciable difference from my PC.
You can also log dropped packets targeted at port 5678 (add log=yes to filter entry) … stop winbox for a few hours and later check log to see if timestamps are consistent with winbox usage or not.