While many of you are notably upset about the extraordinary amount of time that has gone by on this issue. I note some of you are wanting to move to new product vendors. This is your prerogative to do so. That said, I will point out the BIG VENDORS such as CISCO are smashed by CVE's problems ALL the time. Mikrotik is doing pretty well on the CVE footprint issue comparatively.
They are doing well on the ones that go public, yes. The issue here is not just these issues. It's the whole approach on handling support requests and the time it takes to get a response, changing things in RouterOS effectively breaking working features without even discussing the reasoning for these changes, not implementing fundamental features.
Also, a lot of bugs don't get reported anymore, because we know it doesn't lead anywhere anyhow.
At some point enough, is enough. And yes, other vendors have other issues. Other vendors may also be more costly. But at least other vendors take responsibility for their products, have a clear guideline what a timely response to a ticket is and implement critical features, that customers and the industry needs. Again .. a good example: it's taken Mikrotik over a decade to implement IPV6-Delegated-Prefix, but then they decided only to implement it for DHCP and not for PPPoE. I mean .. where is the logic in that ?
They have also recently (as of 6.43) made it mandatory to use MS-CHAP for user-authentication via radius. So whoever was using CHAP .. which would be an industry standard .. vs MS-CHAP being a proprietary extension ... got their entire setup broken.
These are just example that show how they treat their customers.
The handling of these 2 CVEs reflect the same fundamental problems within Mikrotik. A workaround then gets posted for one of the issues, that works for an end-user network, but essential would cripple the network of an ISP that has an actual IPv6 rollout with thousands of customers using IPv6. Again ... the bigger picture gets missed. Because is Mikrotiks biggest market end-users ? or providers ?