Last week I picked up a brand new CCR2116-12G-2S+ at the local electronics recycling facility.
The place is basically a large dumpster where people, and companies throw away their electronics.
Well... the CCR2116 came with the latest HW rev. r2 and manufactured in Sept-2025. Sold at half price, unopened, unused. They also had a brand new CCR2004-16G-2S+ (also the latest HW rev. r3). Also at a half-price.
The CCR2116 came with user admin and a blank password. Likely a government purchase, that didn't meet their strict compliance.
Souldn't it be a question to these people who dumped devices?
Do you ask KFC/MCDonald/BurgerKing "what's wrong with them" when they dump unused&unpacked food just beacause it's the end of day and they have to throw it, not to give to people?
The purchaser is in strict compliance with the security procedures, and did the right thing by dumping the products.
Mikrotik, and its partners who sold the product in Canadian market have both likely lost more than a government customer.
I had quite a lot of MT boxes in my hand and never saw any "onece apllied, no way to remove" sticker that could prove that the box/device had not been opened. Maybe I have been missing something but I doubt.
Maybe someone bought "a toy for big boy" and felt overhelmed with it and just dumped it?
It even states that it is applied just to THEIR devices
"The Gov of Canada maintains strict satndard for passwords to protect ITS digital infrastructure"
Mikrotik itself has announced a shift to new password policy back in April of 2023, and this was likely so they could sell their products to governments. Obviously a Quality issue at Mikrotik. There is no point discussing the topic any further.
So you think they were discounted because they come with a blank password? I doubt that.
My guess: more likely some company bought some for testing/potential use & found RouterOS too complex. And when its OPM (other-peoples-money), it's often quicker to just have an ewaste company dispose of them than learn RouterOS to re-purpose them or some IT department being distracted by re-selling devices...
I am certain that this is the case. The one I picked up came with the blank sticker. Now, if you look at a big picture: we have a new PM in Canada, and he goes big on Cyber + Defense spending. Although, in this case it was probably Municipality that bought Mikrotiks as it just began spending new money like crazy for infrastructure all over the city in the past few months.
Now if you look at the ongoing trade war with US... CISCO falls out of favour. And according to public information Canada now trades with Nordic EU countries (hint, hint), so Mikrotik comes handy.
Next, to your questions, I think the Techs were actually the ones who liked Mikrotiks, but devices came with blank passwords, so they did the right thing and reported non-compliance. The Management on their part wouldn't put their a** (pay stubs) on the line. Noone ever gets fired for doing their job, and following the procedures. So the non-compliant products get recycled because the government isn't allowed to use them.
Now, the funny part. What I believe has actually taken place is: Mikrotik will just send them replacement, and swallow the cost, so not to lose the customer/market share.
All of that makes me think to go get Tik certification and become one of the authorized reps in the area.
As a said, IDK. We're both speculating. You got a deal, somehow, on them - that seems like a good thing since adding a password is trivial. So I really not sure your point here, still.
But why would be on a recycle site for you buy? I doubt MikroTik eat the cost of them, and want to RMA the units. But again IDK and it's does not matter.
If they were going to be disqualified from government use... there are MANY typical security policy things that RouterOS might also fail – the lack of RBAC, encryption schemes, certifications, some 2FA scheme, delegated admin, AD/LDAP/etc integration, or bunch of other things.
AFAIK, some shipping device still don't come default password. I don't know on your specific models however. The default password policy applied to "home routers" not all units, again AFAIK.
Hmm....
How do they decided that there is no default password? Just because of sticker on the chasis? It means that the box was opened. Maybe they connected the device and saw that there is no password, so device was used. Maybe the new sticker was in the box? Who knows?
The main questions are:
Was it netinstalled and password is blank now?
What is the factory firmware? Lower han the firmware that is installed now or the one that was when you bought it?
No matter what are the answers I would like to have such a dumpster place nearby to get such bargains.
As long as first access mandates a password be set, and blank is not allowed, it seems to require a pretty massive level of stupidity to mandate a password on an undeployed, unconfigured device . . . . (but then again, that's a big part of gov't - regulate what isn't a problem, and ignore what actually is . . . ) YMMV.
Seems like a lot of the security mandates these days are more about "feels good! Look what we did!" by the rule makers as opposed to anything that actually helps . . .
This one is easy to answer - I purchased one - it's in my city. I bought from them various products before. Never had issues with returns, or cancelling the bid. CCR2116 came brand new. In box, with default login = admin, and blank password. Out of the box it had zero sectors written (100+ some sectors written on the first start I believe). Came with RouterOS 7.19.6 as seen below.
It is interesting that instead of Mikrotik logo the sticker comes with "TEC" logo and MTCTE: # which I believe is "Mikrotik Certified Traffic Control Engineer" certificate (can be seen on my previous photo).
So I would say, when you bought this in Canada. Could be a grey import from India. And maybe Mikrotik still produces Admin without password for that market?
maybe Mikrotik still produces Admin without password for that market?
Good point. Recyclers have many lines of business: They are contracted by governments to securely recycle data-sensitive electronics from big 3-digit Agencies. They also operate retail outlets selling to home lab crowds. If they are successful at reselling junk (keeping electronics out of landfills) - they get free money in the form of government grants.
They also buy and sell electronics wholesale (large containers by weight) - in international markets. I know that one in my city ships container loads of electronics to Africa.
As fas as I remember, our CCR2216s shipped without individual passwords, whereas the RB5009 and hex came with stickers with individual passwords nicely printed in unreadably small font.
I do not know the exact regulations as I am not from Canada. I understood the directive that it is not allowed to deploy infrastructure with empty passwords. I did not read from it that you are not allowed to sell hardware without passwords. After all, an unconfigured CCR2216 is pretty useless as it basically has no configuration at all and exposes services that you probably do not want to expose to the internet.