Search changelog entries
| Component | Change |
|---|---|
| certificate | added "ISRG Root X2", "Root YE" and "Root YR" to SMIPS built-in root certificate authorities store; |
| certificate | added "Root YE" and "Root YR" to built-in root certificate authorities store; |
| defconf | added virtual "iot-wifi" to MLO supporting devices; |
| dhcpv4-server | fixed "expires-after" field for disabled static lease (introduced in v7.23); |
| fastpath | properly fall back to SlowPath when FastPath is not possible due to fragmentation; |
| ipsec | fixed identity lookup to skip past disabled and certificate-matched identities when scanning for an exact ID match; |
| ipsec,ike2 | improved logging when remote ID is specified; |
| ipsec,ike2 | use peer certificates also when identity has one set for peer matching; |
| ipv6,ra | show warning about paused automatic RA on upgraded routers; |
| ospf | fixed "duplicate config" issue when using ptp-unnumbered interface type; |
| ptp | fixed a race condition when reading transmit timestamps, which could cause unstable clock offset under background traffic; |
| ptp | fixed PTPv1 traffic forwarding when a PTPv2 profile is enabled on bridge ports; |
| snmp | improved SNMPv3 request processing logic; |
| system | added microSD card support for hAP be3 Media; |
| system | improved handling of data re-sending on authorization requests (introduced in v7.22); |
| system | improved stability; |
| system | updated certificate for Windows executable signing; |
| tftp | limit maximum simultaneous session count to 100; |
| Component | Change |
|---|---|
| bridge | fixed MLAG MAC address handling issues related to aging, flushing and moving (additional fixes); |
| crypto | fixed hardware accelerator for GCM cipher in TLS connection on Alpine CPUs; |
| defconf | added virtual "iot-wifi" to MLO supporting devices; |
| ethernet | fixed stability issue for Chateau PRO ax devices (additional fixes); |
| ip | improved stability for reverse-proxy; |
| ipsec | fixed identity lookup to skip past disabled and certificate-matched identities when scanning for an exact ID match; |
| ipv6,ra | show warning about paused automatic RA on upgraded routers; |
| isis | fixed ECMP route removal; |
| l3hw | added HW offloaded VRF support on 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98CX8410 switches (additional fixes); |
| l3hw | added VRF assignment via switch ACL rules for devices with Marvell Prestera switch chip; |
| l3hw | allow VLAN tagged traffic inside VXLAN tunnel (additional fixes); |
| l3hw | fixed VRF-related issues for CRS8xx series switches; |
| lte | improved USB mode handling for BG770A-GL; |
| ospf | fixed "duplicate config" issue when using ptp-unnumbered interface type; |
| ptp | fixed a race condition when reading transmit timestamps, which could cause unstable clock offset under background traffic; |
| ptp | fixed PTPv1 traffic forwarding when a PTPv2 profile is enabled on bridge ports; |
| snmp | added hotspot active-user-count and host-count OIDs to MIKROTIK-MIB; |
| snmp | added missing SFP OIDs to MIKROTIK-MIB; |
| system | added microSD card support for hAP be3 Media; |
| system | improved stability; |
| upgrade | removed sensitive policy for "apply-changes" command; |
| wifi | improved roaming/steering behavior for WiFi 7 MLO (additional fixes); |
| Component | Change |
|---|---|
| bridge | fixed MLAG MAC address handling issues related to aging, flushing and moving (additional fixes); |
| certificate | added "ISRG Root X2", "Root YE" and "Root YR" to SMIPS built-in root certificate authorities store; |
| certificate | added "Root YE" and "Root YR" to built-in root certificate authorities store; |
| dhcpv4-server | fixed "expires-after" field for disabled static lease (introduced in v7.23); |
| dns | fixed an issue where the resolve command was not functional when the "type" was specified (introduced in v7.24beta2); |
| fastpath | properly fall back to SlowPath when FastPath is not possible due to fragmentation; |
| ipsec,ike2 | use peer certificates also when identity has one set for peer matching; |
| l3hw | allow VLAN tagged traffic inside VXLAN tunnel (additional fixes); |
| netinstall | added Netinstall package (additional fixes); |
| snmp | added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIB; |
| snmp | improved SNMPv3 request processing logic; |
| ssh | make SSH packet validation more strict (additional fixes); |
| system | improved handling of data re-sending on authorization requests (introduced in v7.22); |
| system | improved stability; |
| system | updated certificate for Windows executable signing; |
| tftp | limit maximum simultaneous session count to 100; |
| usb | fixed USB Ethernet interface default-name; |
| wifi | improved roaming/steering behavior for WiFi 7 MLO (additional fixes); |
| wireguard | added support for domain names in client-dns; |
| wireguard | added warning when allowed-address overlaps with another peer on the same interface; |
| wireguard | fixed wg-export comments output and case when endpoint is not set; |
| wireguard | fixed whitespace handling in AllowedIPs during wg-import; |
| wireguard | improved wg-export to print endpoint domain name; |
| wireguard | improved wg-import to quietly ignore wg-quick specific keys; |
| wireguard | reconfigure peer only when meaningful changes are detected; |
| Component | Change |
|---|---|
| app | fixed "reset" not working with certain apps; |
| app | fixed home-assistant default config files; |
| app | only generate secrets for enabled apps; |
| app | resolved issue where duplicate swaps are created; |
| bfd | fixed delay on session print; |
| bgp | added option to add BGP VPLS created interfaces in interface-list; |
| bgp | fixed advertisement print handling by "dst" when destination is in VRF; |
| bgp | fixed IPv6 End-of-Route processing; |
| bgp | improved stability on MP (multiprotocol) parsing; |
| certificate | always use all trust stores for downloaded CRL validation; |
| container | fixed missing config.json issue when upgrading from version 7.20.8 or older; |
| interface | fixed duplicate MAC warning for wireless, wifi, macsec, w60g interfaces (introduced in v7.23); |
| ipsec | fixed policy move handling; |
| ipsec,ike2 | fixed active connection termination; |
| ipsec,ike2 | fixed SA payload validation; |
| ipsec,ike2 | improved pending child SA cleanup and removal of dangling SAs during Phase 2 deletion; |
| isis | fixed missing "l2.lsp-refresh-interval" parameter; |
| leds | fixed missing wireless LED configuration (introduced in v7.21); |
| lte | fixed cases where EC25-EU and EG25-G boards would receive packets with missing last 4 bytes; |
| ospf | added missing "type=ptmp-broadcast" parameter to "/routing/ospf/interface" menu; |
| ospf | allow comments on static interfaces; |
| ospf | fixed interface passive flag update in WinBox; |
| pim | added comment for "/routing/gmp" entries; |
| ppp | improved system stability; |
| route | fixed static route flag handling by WinBox on disable; |
| routerboard | renamed "ipq53xx" firmware type to "ipq5300"; |
| switch | increase "ingress-rate" and "egress-rate" maximum value to 400G; |
| upgrade | prevent package scheduling from interfering with the upgrade feature; |
| winbox | added missing values to "AFI" setting under "Routing/BGP" menus; |
| winbox | do not pre-fill "Allowed Address" and "Client Allowed Address" with "::/0" when adding new WireGuard Peer; |
| winbox | fixed value unset under "MPLS/LDP Neighbor" menu; |
| Component | Change |
|---|---|
| bfd | fixed delay on session print; |
| bgp | fixed advertisement print handling by "dst" when destination is in VRF; |
| bgp | fixed IPv6 End-of-Route processing; |
| bgp | improved stability on MP (multiprotocol) parsing; |
| bridge | fixed dynamic VLAN update for wifi interfaces; |
| bridge | fixed stability issue when using DHCPv4 snooping; |
| cloud | cloud backup file management now requires "policy" policy; |
| console | fixed unresponsiveness when entering safe-mode through the Windows 11 terminal; |
| container | fixed missing config.json issue when upgrading from version 7.20.8 or older; |
| disk | avoid reading SCSI stats all the time to allow disks to go to sleep; |
| ethernet | fixed stability issue with TSO on Alpine CPUs; |
| ethernet | improved system stability on devices with Alpine CPUs; |
| ipv6 | do not disable IPv6 FastPath when Traffic Flow is enabled; |
| isis | allow to configure metric-type; |
| isis | fixed missing "l2.lsp-refresh-interval" parameter; |
| l3hw | improved system stability on device shutdown/reboot; |
| lte | fixed cases where EC25-EU and EG25-G boards would receive packets with missing last 4 bytes; |
| lte | fixed crash on LTE passthrough interface deactivation; |
| ospf | fixed interface passive flag update in WinBox; |
| route | fixed static route flag handling by WinBox on disable; |
| route | removed deprecated "/routing/route/rule" menu; |
| switch | fixed issue with MAC table for RB2011 (introduced in v7.21); |
| switch | fixed rare possibility of tx-timeout or simultaneous flap of all switch ports on devices with Alpine CPUs; |
| switch | increase "ingress-rate" and "egress-rate" maximum value to 400G; |
| timezone | updated timezone information from "tzdata2026b" release; |
| upgrade | prevent package scheduling from interfering with the upgrade feature; |
| vxlan | fixed fast-path when using "checksum=no" (introduced in v7.20); |
| winbox | do not pre-fill "Allowed Address" and "Client Allowed Address" with "::/0" when adding new WireGuard Peer; |