Community discussions

MikroTik App
 
souljazk
just joined
Topic Author
Posts: 17
Joined: Tue Jan 12, 2016 10:05 am

3years no RouterOS updates - would you consider it compromised & replace the unit?

Mon Oct 18, 2021 5:50 pm

HI there,

I was recently referred to a new client, during my initial inspection I noticed the Mikrotik (951Ui) was running FW 6.43.2 (Sep 2018). This is an ISP provided unit that seemed to escape the ISP's 6-month checks for quite some time..

They (ISP) have since updated the router (remotely) to one of the 2021 FW's, but this does not sit well with me,. I air on the side of caution & have mentioned to them (ISP) that they should consider the router as compromised & replace it outright. They (ISP) seem to believe the router has never been compromised, something I struggle to believe due to the fact that the router was left unpatched for so long, despite being "managed".

I would love to hear from Mikrotik & the members on this forum.

Thank you!
Last edited by souljazk on Mon Oct 18, 2021 6:11 pm, edited 1 time in total.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19322
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: 3years no RouterOS updates - would you consider it compromised & replace the unit?

Mon Oct 18, 2021 6:06 pm

Yes, it should be netinstalled with the latest long term firmware, unless the client is a risk taker and absolutely needs wireguard 7.1bRC4
 
ConnyMercier
Forum Veteran
Forum Veteran
Posts: 725
Joined: Tue Dec 17, 2019 1:08 pm

Re: 3years no RouterOS updates - would you consider it compromised & replace the unit?

Mon Oct 18, 2021 6:12 pm

i concur with @anav,

You don't have to replace the device, just do a NetInstall!
It will Clear everything on the Device and install the Linux-kernel and ROUTEROS from scratch
 
souljazk
just joined
Topic Author
Posts: 17
Joined: Tue Jan 12, 2016 10:05 am

Re: 3years no RouterOS updates - would you consider it compromised & replace the unit?

Mon Oct 18, 2021 6:19 pm

@anav & @ConnyMercier

Thank you for your input! In my panic I totally forgot about Netinstall *face palm*. I'll share this with the ISP in question & ask that they comply with an onsite Netinstall.
 
User avatar
BartoszP
Forum Guru
Forum Guru
Posts: 2879
Joined: Mon Jun 16, 2014 1:13 pm
Location: Poland

Re: 3years no RouterOS updates - would you consider it compromised & replace the unit?

Mon Oct 18, 2021 7:05 pm

It's much easier for them to send you repalcement device already configured.
 
User avatar
anav
Forum Guru
Forum Guru
Posts: 19322
Joined: Sun Feb 18, 2018 11:28 pm
Location: Nova Scotia, Canada
Contact:

Re: 3years no RouterOS updates - would you consider it compromised & replace the unit?

Mon Oct 18, 2021 7:26 pm

It's much easier for them to send you repalcement device already configured.
Do you mean configured by the Red Army or the ISP, same thing if in China ;-)

Who is online

Users browsing this forum: Bing [Bot], hkimyafay, markmoore and 40 guests