The dojo blog.
Vulnerabilities explained with the commands to protect yourself, RouterOS updates to know before installing them, news and products — in English, from official sources.

Critical vulnerability in the RouterOS container package
CVE-2022-34960 is a critical vulnerability (CVSS 9.8) in the MikroTik RouterOS 7.4beta4 container package that allows an attacker to mount arbitrary files at any location on the host device. It exclusively affects administrators who have installed and enabled the container package in device mode. Immediate mitigation consists of updating to a fixed version or disabling the service if not used.
DojoSend emails from MikroTik with Gmail: SMTP and app passwords
A MikroTik can send emails (alerts, backups, reports) using a Gmail account as the SMTP server: smtp.gmail.com, port 587, STARTTLS. However, the password is not the account password: you need an app password, which Google only issues when two-step verification is enabled. In RouterOS 7, the configuration is located in /tool e-mail.
SecurityBuffer overflow in the RouterOS SCEP server
CVE-2021-41987 is a critical vulnerability (CVSS 8.1) in the RouterOS SCEP server that allows remote code execution. It affects versions 6.46.8, 6.47.9, and 6.47.10. You must update the firmware to a later version not listed as vulnerable or disable the SCEP service if not in use.
SecurityBuffer overflow in the FTP service of RouterOS 6.47
CVE-2020-22845 is a buffer overflow in the FTP service of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service via malicious FTP requests. The vulnerability has HIGH severity (CVSS 7.5) and specifically affects version 6.47. To mitigate the risk, you must update to a later version or disable the FTP service if not strictly necessary.
SecurityBuffer overflow in the SMB server of RouterOS
CVE-2020-22844 is a buffer overflow in the SMB server of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service through malicious SMB requests. The vulnerability specifically affects version 6.47 and is not known to be actively exploited. To mitigate the risk, you must update the firmware or disable the SMB service if it is not in use.
ProductsChateau 5G R16: 5G Router with RouterOS and Linux Containers
The Chateau 5G R16 is a mobile 5G router designed to provide high-speed connectivity in home and office environments, integrating the flexibility of RouterOS v7. It stands out for its support of Linux containers, allowing you to run applications like PiHole or Home Assistant directly on the device, in addition to a Sub-6 5G radio with NR CA and ENDC support.
SecurityArbitrary File Write via FTP in RouterOS
CVE-2021-27221 allows a remote authenticated user with an FTP policy to create or overwrite arbitrary .rsc files using the /export command. This flaw affects RouterOS 6.47.9, where the vendor considers this behavior intentional due to how user policies work. To mitigate the risk, you must disable the cleartext FTP service or ensure that only trusted users with appropriate policies can access it.
SecurityReflected XSS in the Hotspot login page
CVE-2021-3014 is a reflected Cross-Site Scripting (XSS) vulnerability in the Hotspot service login page in MikroTik RouterOS. It affects RouterOS versions published up to January 4, 2021. To mitigate the risk, you must update the firmware to a later version or disable access to the Hotspot login page from untrusted networks.
ProductsMikroTik CRS520-4XS-16XQ-RM: 100G enterprise switch
The MikroTik CRS520-4XS-16XQ-RM is a high-performance enterprise switch designed for data centers and complex networks. It features a 2 GHz quad-core ARM CPU, typical of the CCR series, enabling advanced routing and management functions beyond simple switching. It offers 16 100 Gigabit QSFP28 ports and 4 25 Gigabit SFP28 ports in a single rackmount chassis.
SecurityInteger underflow in the RouterOS SMB server
CVE-2019-16160 is an integer underflow in the RouterOS SMB server that allows an unauthenticated remote attacker to crash the service. RouterOS versions prior to 6.45.5 are affected. To mitigate the risk, upgrade to a later version or disable the SMB service if not required.
SecuritySMB server crash in RouterOS
CVE-2020-11881 is an array index validation error in the RouterOS SMB server that allows a remote unauthenticated attacker to cause a service crash. It affects versions 6.41.3 through 6.46.5 and 7.x versions up to 7.0 Beta5. Immediate mitigation is to disable the SMB server if not strictly necessary, as the stable fixed version is not specified in the available data.
SecurityPlaintext password in the WinBox configuration file
WinBox 3.22 and earlier versions save the user password in unencrypted text in the configuration file if the "Keep Password" option is enabled and no Master Password is set. Since these are the default settings, an attacker with access to the file can recover the credentials to access the router. You must update WinBox to a later version or disable the password saving option.
DojoUnauthorized DHCP server: how to detect and block it with MikroTik
An unauthorized DHCP server, often a mall WiFi router connected "backwards", can bring a LAN to its knees in minutes. With MikroTik, you can detect it using /ip dhcp-server alert, which notifies you when a server other than the valid one responds, and block it using bridge DHCP snooping, which in RouterOS 7 accepts DHCP responses only from trusted ports.