Hello,
I found on 5 of my Mikrotik router with v6.42.3 some weird connection.
See attachment.
The change made by the remote logging that come from china, is Changed telnet port back to 23, changed ssh port back to 22.
Look like an automatic process, because 5 router have the connection at the same time…
What do you think about that?

Do you have a password on admin account?
Do you have the API accepted in your firewall?
Yes, we have a complicated password on the admin account, API are enable from outside. The 5 router don’t have the same password, so I am very concerned about a security issue.
If you actually have a decent password on the account…
Despite that you have opened the API to outside world… you should generate a support file and send it to Mikrotk ASAP with an explanation.
Log says IP services were adjusted. What changed?
SSH port changed from custom port to 22
Telnet port changed from custom port to 23.
Mikrotik Support say, my password was probably stolen when the router was on 6.41 , and now something try to use it.
All our Mikrotik password was changed now so problem should be solved…