
Hotspot
Hotspot, captive portal, PPPoE for users: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

Hotspot and PPPoE MikroTik: the username in every log line
Hotspot connection logs contain IP addresses, not people: to find out who was behind an address, you must cross-reference it with the logins. Using a login and logout script, you can create a log rule for each connected user, with the username in the log-prefix: every log line already contains the name. This works with the hotspot (on-login / on-logout of the user profile) and with PPPoE (on-up / on-down of the PPP profile).
SecurityXSS in RouterOS Hotspot
CVE-2025-6563 is a cross-site scripting (XSS) vulnerability in the RouterOS hotspot service in versions prior to 7.19.2. An attacker can inject JavaScript code via the dst parameter to execute scripts in the victim's browser upon login. To mitigate the risk, you must update to version 7.19.2 or later.
DojoMikroTik Hotspot: How to Log User Traffic
In a hotspot, users access the internet through a single public IP address: to determine who did what, you need a connection log. With RouterOS 7, this is generated using a firewall rule with action=log applied only to new connections, and sent to an external syslog server, because the router's memory is not an archive. Alternatively, or in addition, you can use Traffic Flow (IPFIX/NetFlow) towards a collector.
SecurityOut-of-bounds Read in the Hotspot Process
CVE-2022-45313 is an Out-of-bounds Read vulnerability in the hotspot process of RouterOS, allowing arbitrary code execution via a manipulated nova message. It affects RouterOS versions prior to 7.5. To mitigate the risk, you must update to a stable version later than 7.5 or disable the hotspot service if not in use.
DojoHotspot 2.0 and Passpoint with MikroTik: Interworking in the WiFi Package
Hotspot 2.0 (commercial name Passpoint, underlying standard 802.11u) allows a phone to automatically and securely connect to a public WiFi network without a login page, recognizing its own carrier or organization. In 2017, I discovered an undocumented menu in RouterOS 6; today, the WiFi package in RouterOS 7 includes an official menu, /interface wifi interworking, to be used together with a RADIUS server.
SecurityReflected XSS in the Hotspot login page
CVE-2021-3014 is a reflected Cross-Site Scripting (XSS) vulnerability in the Hotspot service login page in MikroTik RouterOS. It affects RouterOS versions published up to January 4, 2021. To mitigate the risk, you must update the firmware to a later version or disable access to the Hotspot login page from untrusted networks.
DojoMikroTik Hotspot: Protecting the LAN from WiFi Clients
In a MikroTik hotspot, guest clients must not be able to reach the customer's network (servers, printers, NAS). A single firewall rule using the hotspot=from-client matcher is enough; if the network to protect is not known in advance because the WAN gets its address via DHCP, a DHCP client script automatically updates it in an address list.
DojoHow to create a WiFi hotspot with MikroTik and RouterOS 7
A WiFi hotspot with a captive portal on MikroTik is built in seven steps: reset, WAN, guest network on a bridge, radio, /ip hotspot setup wizard, test, and final cleanup. In RouterOS 7, the radio part changes significantly, as recent models use the new wifi package instead of wireless. The addresses in the example are from my lab: adapt them to your network.