MikroTik security findings, explained
Every finding the audit can report has its own page: what it means, why it matters, what it looks like in Winbox, and the exact RouterOS commands that fix it. Written for people who run a MikroTik router, not only for security specialists.
Default SSID "MikroTik": what a factory network name tells attackers
A WiFi network still called MikroTik or MikroTik-XXXXXX announces the make of your router to everyone in range and suggests the rest of the setup is factory default too. It is not a hole, but it is a signpost. Renaming it takes one command.
Open WiFi network without encryption
One of your access points broadcasts a network with no WPA2 or WPA3 at all. Anyone in range can join, and everything clients send without HTTPS can be read from the car park. Here is how to add encryption, or isolate the network if it must stay open.
Router management reachable from an open WiFi
Your open wireless network is bridged to an interface from which the router's own login services can be reached. Anyone within radio range can try to log in, and a captive portal does not stop them. Two firewall rules fix it.
Your SSID contains a name, phone number or e-mail
A WiFi network name is broadcast to everyone in range and collected by public mapping databases. When it contains a surname, a phone number or an e-mail address, it ties a person to a physical location. A neutral name is a quick fix.
WiFi still allows WPA1 / TKIP
A security profile on your access point still allows WPA1 or the TKIP cipher. Both are cryptographically broken, and TKIP also caps the network at legacy speeds. Allow WPA2 with AES and WPA3 only.
WPS is enabled on your WiFi
WiFi Protected Setup lets a device join your network by pressing a button on the router instead of entering the passphrase. Anyone with a moment of physical access can do the same. Disable it unless you actively use it.
New article every other day · RSS