Security
- MikroTik's 3 September security release was not being reported as one. The fixes in 7.24.2, 7.23.4 and 6.49.21 carry no CVE number and no detail — MikroTik withheld both on purpose to give people time to upgrade — and the warning is written as a sentence above the change list rather than as a marked entry. mikr only read the marked entries, so devices sitting below those versions were shown as ordinary out-of-date, with nothing to say a security fix was waiting. Security notices written above the list are now read as well. A device on 7.24.1 is offered 7.24.2, and one on 7.23.3 is offered 7.23.5, both on the Security page and on the device's own page. As before, mikr says only that a security release exists on your branch and you are below it — never that your device is vulnerable, which the changelog does not state.
- A device RouterOS has flagged is now shown as flagged. RouterOS checks its own configuration when it starts, and if it finds signs of a break-in it switches the offending settings off and marks the device. A marked device will not run a bandwidth test, traffic generator or sniffer, and will not let anything create a new scheduler, SOCKS, PPTP, L2TP, IPsec, proxy or SMB entry. MikroTik's advice is to assume the device was compromised. Until now that warning lived only on the device itself: mikr now reads it hourly and shows it as a red banner on the device page, a flagged badge on the device card, and the first entry of the issues report. Clearing the flag has to be done at the device — it needs a button press or a power cycle — so mikr reports it and never touches it.
Added
- The device page now states the device-mode RouterOS is running in, and which RouterOS versions the device will accept. A board that refuses an upgrade because of its own policy otherwise looks exactly like a network problem.