What changes in RouterOS after the update?

After the update, RouterOS automatically performs a check to verify whether the device has been compromised. If it detects a compromise, it sets the device status to “Flagged” and logs a critical event in the “Log” section. It is important to note that the “Flagged” status does not remove the existing configuration; the administrator must still manually inspect the configuration for scripts, users, or other unknown entries.

Who should update (or not update)?

All users should update, including those with home devices and default configurations. The announcement specifies that for the latter, the risk is not immediate, but the update is still recommended to ensure security. There are no exclusions: the update is available in all release channels.

How to update (or remediate) safely?

To update, use the “Check for updates” menu on the device, which should already show the option for the software update. After the update, check the “Log” section for any critical entries related to the “Flagged” status. If present, follow the instructions in the documentation regarding the Flagged status. In any case, inspect the configuration for unrecognized elements.

Frequently asked questions

Does RouterOS 7.24.2 fix the vulnerability?

Yes, RouterOS 7.24.2 is one of the versions that includes the fix for the security vulnerability. The other fixed versions are 7.25 beta 3, 7.23.4, and 6.49.21.

What does the “Flagged” status mean in RouterOS?

The “Flagged” status indicates that RouterOS has detected a possible compromise of the device after the update. This status is recorded in the logs and requires action from the administrator, but it does not automatically remove the existing configuration.

Do I need to delete the configuration if the device is Flagged?

No, the “Flagged” status does not delete the configuration. However, you must manually inspect the configuration to remove any scripts, users, or other unknown entries that may have been added by an attacker.

Is the update available in all channels?

Yes, the versions with the fix have been published in all release channels, including stable, long-term, and testing.

Source: official MikroTik announcement on the forum.