enjoy
fileremove.rsc (204 Bytes)
reboot.rsc (227 Bytes)
MIKROTIK-UTIL-ENG.zip (3.79 KB)
Upgraded RB2011, no issues so far.
Yeah… your avatar is pretty self-explaining.
Found a smal bug that should be fixed.
In GUI name “Tools” is used.
In CLI it is used “tool”
Using same name helps to navigate when using both interface CLI and GUI
Other strange thing.
In GUI Bridge has its own main menu.
In CLI its under Interface/Bridge
Why these differences?`
There are some GUI differences for ease of use. It is not v6.42.7 specific.
Is there any indication of the attack surface of “vulnerabilities CVE-2018-1156, CVE-2018-1157, CVE-2018-1158, CVE-2018-1159”?
What kind of installations would be directly at risk and require quick updates?
(e.g. admin service ports open on internet, certain types of VPN service open on internet, any configuration with internet connection, etc)
Can you provide some more informations about fixed vulnerabilities? eg. how critical are? thanks
Posted in wrong thread, should be in the Winbox thread.
PS it does not make it simpler to not have equal name and stricture.
This would be really nice to know!
We will publish official blog post soon with more detailed information about the fixed vulnerabilities.
Were these security fixes stealthily added to the v6.42.7 patch notes? I don’t recall seeing them there before and I didn’t update since it didn’t look like a necessary update. It’s very bad that details aren’t available even though the fixed version is published. It doesn’t take much effort to compare the 6.42.6 vs 6.42.7 binaries and figure out where the exploits were and start attacking them. Hopefully this is just a fix of long standing security bugs like lack of certificate validation in numerous places.
Upgraded RB951Ui, no issues so far.
Best regards: CsXen
I can confirm that the security fixes were added to the notes after the 6.42.7 thread was already posted! Why was this?

@rushlife: Thank you for the scripts!
Well after realizing I was more dangerous then helpful I decided to lay low for awhile.
Now I will post if I have some certainty and quality of input (thus crickets chirping from me) or have a healthy dose of humour/sarcasm to inject.
I must say I am screaming through so many TV series these days its all a blur. (Right now its the “Shooter” and “Justified”)
!) security - fixed vulnerabilities CVE-2018-1156, CVE-2018-1157, CVE-2018-1158, CVE-2018-1159;
6.42.6 is vulnerable to this?
Upgraded RB3011. Ipsec tunnels broken
RB750Gr3,. Ipsec tunnels broken ,
Reverted back to 42.6 , all ipsec tunnels back working well ,
Updated seveal routers, amongst them some RB750Gr3, no such problem noticed.
Exchange mode and policy type (tunnel/transport) may both make a difference.
@R1CH: Yes, it was not here. Probably they needed to wait for 6.40.9 to ne released too. The the information was added to both.
I do not see problem to release more information later. Maybe it is about to give people some time to upgrade before releasing details.
@chechito: Are you serious with your question ???
Well, the problem I have is that I now need to update many routers because they may be vulnerable and taken over tomorrow, and then
when further details emerge it may be that we are not using the vulnerable feature or have the proper firewalling.
So I would have appreaciated some summary of attack surface as I requested above. It would save me a night of overtime.