Build Time: 2026-09-03 10:44:35 UTC (1788432275)
Architecture: arm64
Channel: long-term
RouterOS
Type
File
Main package
routeros-7.23.4-arm64.npk
Extra packages
all_packages-arm64-7.23.4.zip
ISO Image
mikrotik-7.23.4-arm64.iso
Cloud Hosted Router (CHR)
Platform
UEFI
Raw disk image
chr-7.23.4-arm64.img.zip
Open Virtual Appliance
chr-7.23.4-arm64.ova.zip
QEMU/KVM
chr-7.23.4-arm64.qcow2.zip
VirtualBox
chr-7.23.4-arm64.vdi.zip
Hyper-V (legacy)
chr-7.23.4-arm64.vhd.zip
Hyper-V
chr-7.23.4-arm64.vhdx.zip
VMware
chr-7.23.4-arm64.vmdk.zip
Changelog
What's new in 7.23.4 (2026-09-03):
This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information.
*) bgp - fix BGP link-local nexthops unreachable over a VRF and a crash when disabling an unnumbered connection;
*) btest - improve stability;
*) certificate - fix changing the built-in trust store setting (introduced in 7.22.2);
*) console - improve stability;
*) dhcp - improve stability of DHCP handling;
*) disk - improve stability of the SMB server;
*) fetch - improve stability of the TFTP client;
*) ipsec - fixed expired SA handling to prevent "no such item" errors during listing;
*) ipsec - improve IKE handshake stability;
*) leds - improved interface stats activity for devices with Marvell Prestera switch chip;
*) lte - removed extra restart after firmware upgrade for EC200A-EU modem;
*) lte - fix the RG650E-EU modem not bringing link up after a firmware update;
*) ping - add parameter checks for arp ping;
*) snmp - properly validate password length when applying configuration;
*) ssh - refactor SSH internal processes and improved system stability;
*) system - improve handling of invalid SSL/TLS requests;
*) system - improve stability;
*) tunnel - fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22);
*) webfig - improve stability;
*) wifi - updated radio regulatory information;
*) winbox - fix the "addresses" spelling in read-only fields;
*) wireguard - fixed peer Tx/Rx counters;
*) wireguard - generate port number when specified as zero;
*) wireguard - reinitialize socket on VRF change;
*) www - improve stability;