Skip to content
Topic

Hotspot

Hotspot, captive portal, PPPoE for users: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per Hotspot e PPPoE MikroTik: il nome utente in ogni riga di log
Dojo
Howto · Hotspot

Hotspot and PPPoE MikroTik: the username in every log line

Hotspot connection logs contain IP addresses, not people: to find out who was behind an address, you must cross-reference it with the logins. Using a login and logout script, you can create a log rule for each connected user, with the username in the log-prefix: every log line already contains the name. This works with the hotspot (on-login / on-logout of the user profile) and with PPPoE (on-up / on-down of the PPP profile).

5 min read
Illustrazione per CVE-2025-6563Security
CVE-2025-6563

XSS in RouterOS Hotspot

CVE-2025-6563 is a cross-site scripting (XSS) vulnerability in the RouterOS hotspot service in versions prior to 7.19.2. An attacker can inject JavaScript code via the dst parameter to execute scripts in the victim's browser upon login. To mitigate the risk, you must update to version 7.19.2 or later.

Medium · 4.8
Illustrazione per Hotspot MikroTik: come registrare il traffico degli utentiDojo
Howto · Hotspot

MikroTik Hotspot: How to Log User Traffic

In a hotspot, users access the internet through a single public IP address: to determine who did what, you need a connection log. With RouterOS 7, this is generated using a firewall rule with action=log applied only to new connections, and sent to an external syslog server, because the router's memory is not an archive. Alternatively, or in addition, you can use Traffic Flow (IPFIX/NetFlow) towards a collector.

Illustrazione per CVE-2022-45313Security
CVE-2022-45313

Out-of-bounds Read in the Hotspot Process

CVE-2022-45313 is an Out-of-bounds Read vulnerability in the hotspot process of RouterOS, allowing arbitrary code execution via a manipulated nova message. It affects RouterOS versions prior to 7.5. To mitigate the risk, you must update to a stable version later than 7.5 or disable the hotspot service if not in use.

High · 8.8
Illustrazione per Hotspot 2.0 e Passpoint con MikroTik: l'interworking nel pacchetto wifiDojo
Howto · WiFi

Hotspot 2.0 and Passpoint with MikroTik: Interworking in the WiFi Package

Hotspot 2.0 (commercial name Passpoint, underlying standard 802.11u) allows a phone to automatically and securely connect to a public WiFi network without a login page, recognizing its own carrier or organization. In 2017, I discovered an undocumented menu in RouterOS 6; today, the WiFi package in RouterOS 7 includes an official menu, /interface wifi interworking, to be used together with a RADIUS server.

Illustrazione per CVE-2021-3014Security
CVE-2021-3014

Reflected XSS in the Hotspot login page

CVE-2021-3014 is a reflected Cross-Site Scripting (XSS) vulnerability in the Hotspot service login page in MikroTik RouterOS. It affects RouterOS versions published up to January 4, 2021. To mitigate the risk, you must update the firmware to a later version or disable access to the Hotspot login page from untrusted networks.

Medium · 6.1
Illustrazione per Hotspot MikroTik: come proteggere la LAN dai client WiFiDojo
Howto · Hotspot

MikroTik Hotspot: Protecting the LAN from WiFi Clients

In a MikroTik hotspot, guest clients must not be able to reach the customer's network (servers, printers, NAS). A single firewall rule using the hotspot=from-client matcher is enough; if the network to protect is not known in advance because the WAN gets its address via DHCP, a DHCP client script automatically updates it in an address list.

Illustrazione per Come creare un hotspot WiFi con MikroTik e RouterOS 7Dojo
Howto · Hotspot

How to create a WiFi hotspot with MikroTik and RouterOS 7

A WiFi hotspot with a captive portal on MikroTik is built in seven steps: reset, WAN, guest network on a bridge, radio, /ip hotspot setup wizard, test, and final cleanup. In RouterOS 7, the radio part changes significantly, as recent models use the new wifi package instead of wireless. The addresses in the example are from my lab: adapt them to your network.