Software-update: RouterOS 7.23.2

RouterOS logoMikroTik heeft versie 7.23.2 van RouterOS uitgebracht, een besturingssysteem dat zich richt op routertaken uitvoeren en meer. Denk daarbij natuurlijk aan netwerkverkeer routeren, maar ook aan bandbreedtemanagement, een firewall, draadlozeaccesspoints aansturen, een hotspotgateway en een vpn-server. Het kan zowel op de hardware van MikroTik als op x86- of virtuele machines zijn werk doen. Voor het gebruik is een licentie nodig, die bij de aankoop van MikroTik-hardware is inbegrepen. De changelog voor deze uitgave kan hieronder worden gevonden.

What's new in 7.23.2 (2026-Jul-03 12:08):

!) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;
*) app - fixed "reset" not working with certain apps;
*) app - fixed home-assistant default config files;
*) app - only generate secrets for enabled apps;
*) app - resolved issue where duplicate swaps are created;
*) bfd - fixed delay on session print;
*) bgp - added option to add BGP VPLS created interfaces in interface-list;
*) bgp - fixed advertisement print handling by "dst" when destination is in VRF;
*) bgp - fixed IPv6 End-of-Route processing;
*) bgp - improved stability on MP (multiprotocol) parsing;
*) certificate - always use all trust stores for downloaded CRL validation;
*) container - fixed missing config.json issue when upgrading from version 7.20.8 or older;
*) interface - fixed duplicate MAC warning for wireless, wifi, macsec, w60g interfaces (introduced in v7.23);
*) ipsec - fixed policy move handling;
*) ipsec,ike2 - fixed active connection termination;
*) ipsec,ike2 - fixed SA payload validation;
*) ipsec,ike2 - improved pending child SA cleanup and removal of dangling SAs during Phase 2 deletion;
*) isis - fixed missing "l2.lsp-refresh-interval" parameter;
*) leds - fixed missing wireless LED configuration (introduced in v7.21);
*) lte - fixed cases where EC25-EU and EG25-G boards would receive packets with missing last 4 bytes;
*) ospf - added missing "type=ptmp-broadcast" parameter to "/routing/ospf/interface" menu;
*) ospf - allow comments on static interfaces;
*) ospf - fixed interface passive flag update in WinBox;
*) pim - added comment for "/routing/gmp" entries;
*) ppp - improved system stability;
*) route - fixed static route flag handling by WinBox on disable;
*) routerboard - renamed "ipq53xx" firmware type to "ipq5300";
*) switch - increase "ingress-rate" and "egress-rate" maximum value to 400G;
*) upgrade - prevent package scheduling from interfering with the upgrade feature;
*) winbox - added missing values to "AFI" setting under "Routing/BGP" menus;
*) winbox - do not pre-fill "Allowed Address" and "Client Allowed Address" with "::/0" when adding new WireGuard Peer;
*) winbox - fixed value unset under "MPLS/LDP Neighbor" menu;

Versienummer 7.23.2
Releasestatus Final
Website Fabrikant
Download https://mikrotik.com/download/changelogs?channelFilter=stable&versionFilter=7.23.2
Licentietype Freeware

Door Arnoud Wokke

Redacteur Tweakers

07-07-2026 • 11:51

9

Submitter: J-D

Bron: Fabrikant

Update-historie

Lees meer

Reacties (9)

Sorteer op:

Weergave:

Op de website van Mikrotik stond kort een minder cryptische omschrijving van het security issue namelijk het oplossen van CVE-2026-59108. Ik kan daar echter niets van terugvinden dus wellicht wordt-ie nog even onder de pet gehouden?
In dit topic https://www.reddit.com/r/mikrotik/s/IczdxLydYW op Reddit is wat meer informatie te vinden:
I found the issue, its a heap out-of-bounds read (CWE-125) in ppp with vector: network. I understand why they are withholding it, but it took me a very short time to identify the issue. I trust any attacker could also find it.

If you run an internet-facing PPTP/L2TP/SSTP server you NEED to update immediately. If you run PPPoE server as an ISP you are also vulnerable from any connected client. If you run PPPoE client (to connect to the internet, very common) you SHOULD update as you are still at risk from a malicious PPPoE server (say, your ISP is compromised, because they didn't bother updating).

RCE is unclear; but information disclosure (config files, secret keys, hashed passwords) to an attacker is guaranteed as well as DOS. (W)ISPs or companies running SSL VPNs are most affected. WG/OVPN/IPSEC should not be affected.
Is in NL niet zo relevant dus, daar werken providers veelal met fake credentials op PPPoE niveau en vindt authenticatie plaats op een andere laag (L2 als ik me niet vergis)
Zo simpel is het helaas niet want het gaat erom dat je (configuratie) bestanden op de MikroTik kunt uitlezen. Dus waarschijnlijk ook degene die niks te maken hebben met PPPoE. Zolang de gebruiker in Linux waaronder de PPPoE daemon draait ze maar kan lezen. Ook geven ze aan dat het nog niet duidelijk is of hier wel of niet een remote code execution (RCE) exploit mee gemaakt kan worden:
RCE is unclear; but information disclosure (config files, secret keys, hashed passwords) to an attacker is guaranteed as well as DOS.
Die CVE is kennelijk zo serieus dat er ook een nieuwe LTS versie is (7.21.5) EN zelfs een backport voor 6.49.20
Dus: iedereen aan de upgrade
Ik kocht eind juni een MikroTik, maar toen zij de Routershop dat die pas eind augustus geleverd kan worden.
Welk model heb je besteld?
Voor zover ik kan vinden zou de CVE voornamelijk te maken moeten hebben met PPP/OpenVPN server componenten, dus niet de PPPoE client die bijna iedereen gebruikt.

In dit draadje zal vast en zeker nog meer komen: https://forum.mikrotik.com/t/7-23-2-stable-is-released/271470/43
Ik heb deze software geinstalleerd op mijn hAP ax3 .

Geen problemen ervaren totdat ik onder WiFi - Registration zag dat een aantal clients niet meer verbonden met 5 Ghz AX.

Clients verbonden alleen maar met 2 Ghz N en 5 Ghz AC.

Terug naar software versie 7.21.4 (Long-term) en het probleem was opgelost.

Om te kunnen reageren moet je ingelogd zijn