The official Mikrotik router thread

Sounds like this is a pretty big/important security update that got released today.

I am running on the long-term branch.

What's new in 7.23.4 (2026-09-03):

This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information.




Edit: After upgrading, my DHCPv6 Client stopped working, it gets stuck in a "Searching...." state, so I am stuck without IPv6 connectivity until that gets fixed, or unless I downgrade.
Others are reporting the same issue on the mikrotik forums.
 
Last edited:
Thankfully the DHCPv6 issue was fixed in another urgent release, I have IPv6 connectivity again :)


What's new in 7.23.5 (2026-09-04):



The 7.23.4 release was an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give you time to update your systems, we are not publishing detailed information yet. This release, 7.23.5, additionally addresses an urgent issue introduced in 7.23.4.



*) dhcp - fixed IPv6 DHCP functionality (introduced in v7.23.4);
 
Its a very cute name MikroTrick. Its obviously serious, but not sure how many people this would affect. At a guess well over 90% will never enable SSH, and the ones who do, would likely limit the access.

So its just users who enabled not perhaps knowing what they were doing, users who enabled and forgot to disable, or users who are happy SSH is secure enough in itself.
 
Its a very cute name MikroTrick. Its obviously serious, but not sure how many people this would affect. At a guess well over 90% will never enable SSH, and the ones who do, would likely limit the access.

So its just users who enabled not perhaps knowing what they were doing, users who enabled and forgot to disable, or users who are happy SSH is secure enough in itself.
MikroTik is a hot mess and underpins some of the largest botnets out there. It's a terrible product.
 
MikroTik is a hot mess and underpins some of the largest botnets out there. It's a terrible product.
Terrible product is stretching it. It exposes a lot of configuration / functionality and if you don't know what you're doing it can be a security risk.
 
Its a very cute name MikroTrick. Its obviously serious, but not sure how many people this would affect. At a guess well over 90% will never enable SSH, and the ones who do, would likely limit the access.

So its just users who enabled not perhaps knowing what they were doing, users who enabled and forgot to disable, or users who are happy SSH is secure enough in itself.
The issue is it is enabled by default and ive seen so many peeps using the default config on the tik
 
The issue is it is enabled by default and ive seen so many peeps using the default config on the tik
I remember this as well.

Got to work one day and saw, "Hey I can connect to my Mikrotik".

This was many years ago.

Chatgpt gave me this:

The historical progression​

RouterOS eraDefault firewall behaviourSSH from WAN?
Very old RouterOSSome default configurations had little/no IP firewall protectionCould be accessible
Pre-6.43Default configurations generally had a WAN-interface drop protecting the routerNormally NO
6.43 onwardDefault configuration moved toward interface lists (LAN/WAN) and eventually the !LAN input protectionNO
6.47.xdrop all not coming from LAN was clearly part of the default configurationNO
RouterOS 7.x currentDefault firewall protects router input by allowing LAN and dropping non-LANNO
 
In a interesting predicament at the moment.
Recently used Netinstall to 'format reload' my Mikrotik and loaded a version on there.
It says that a newer version is available for install/ upgrade - but it downloads, installs and then reboots back to the same version.
AI says it is the 'mode" that is set incorrectly, and t set a terminal command, reboot then the upgrade will be possible.
Tried maybe 20x now to get it upgraded.. FML lol
 
Top
Sign up to the MyBroadband newsletter
X