Search changelog entries
| Component | Change |
|---|---|
| bridge | fix host-table entry removal on CRS8xx devices (introduced in v7.25beta4); |
| bridge | warn about VLAN entries when vlan-filtering is disabled; |
| bth | add default client DNS and allowed IPs settings; |
| certificate | refactor certificate internal processes (additional changes); |
| console | fix export order of ordered lists such as firewall filter rules (introduced in v7.25beta3); |
| container | fix veth interface left running after restarting a stopped container; |
| l3hw | optimize ECMP nexthop offloading; |
| leds | fix missing LED triggers when an R11e card is installed; |
| lte | fix missing new firmware update notification on some modems; |
| lte | improve system stability when using Quectel EP06-E MBIM modem (additional fixes); |
| netinstall | add branding-and-custom-packages parameter for custom NPK packages; |
| poe-out | add port-type field to poe monitor and print output; |
| poe-out | firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces); |
| poe-out | firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces); |
| poe-out | fix PoE ports entering overload state when a PSU is fed from a UPS; |
| ptp | fix dropped packets on bridges with IGMP snooping and add vlan-id port setting; |
| sfp | improve QSFP-DD link establishing to NVIDIA DGX Spark and other devices (additional fixes); |
| ssh | add client host key verification; |
| ssh | warn users when weak RSA key is being used (additional fixes); |
| system | improve stability (includes CVE-2026-67280); |
| system | reboot automatically when the boot process fails to start; |
| system | show health settings and overtemp options based on device capabilities (additional fixes); |
| vlan | warn when a VLAN interface is created on a slave interface; |
| webfig | improve comboboxes to select the first matching option while typing; |
| wifi | fix per-link client statistics for MLO connections; |
| wifi-mediatek | fix 4.9 GHz band operation on the A42 (additional fixes); |
| winbox | fix wg-import creating an WireGuard interface without a config file; |
| wireguard | support comment lines in wg-import configuration files; |
| wireguard | treat empty private-key and preshared-key values as none; |
| Component | Change |
|---|---|
| lte | prevent the modem firmware from being deleted for RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, EG25-G&SXTsq (introduced in 7.24.3); If you have already upgraded to 7.23.6 or 7.24.3, follow these steps to restore LTE functionality on affected devices: 1. Upgrade RouterOS to version 7.23.7 or 7.24.4 2. Update the modem firmware: /interface/lte/firmware-upgrade [find] upgrade=yes 3. Reboot the router. For more details, see: https://forum.mikrotik.com/t/warning-lte-interface-stops-working-after-upgrade-to-7-23-6-7-24-3 |
| Component | Change |
|---|---|
| lte | prevent the modem firmware from being deleted for RBSXTLTE3-7, EC25-EU&KNe, EG25-G&KNe, EC25-EU&SXTsq, EG25-G&SXTsq (introduced in 7.23.6); If you have already upgraded to 7.23.6 or 7.24.3, follow these steps to restore LTE functionality on affected devices: 1. Upgrade RouterOS to version 7.23.7 or 7.24.4 2. Update the modem firmware: /interface/lte/firmware-upgrade [find] upgrade=yes 3. Reboot the router. For more details, see: https://forum.mikrotik.com/t/warning-lte-interface-stops-working-after-upgrade-to-7-23-6-7-24-3 |
| Component | Change |
|---|---|
| system | improve stability (includes CVE-2026-67281); |
| Component | Change |
|---|---|
| bgp | improve stability; |
| certificate | add "SSL.com Root Certification Authority ECC" to built-in root certificate authorities store; |
| certificate | allow importing a cross-signed certificate without replacing the existing one; |
| certificate | refactor certificate internal processes; |
| certificate | remove "GoDaddy Class 2 CA" from built-in root certificate authorities store; |
| console | improve stability; |
| crypto | improve stability (CVE-2026-67278); |
| ipsec | fix duplicate connections on IKEv2 retransmissions; |
| ipsec | improve stability; |
| leds | fix LEDs set to interface status staying off when the interface is active; |
| ppp | improve stability; |
| ptp | add manual configuration of PTP message intervals and per-port enabling and disabling; |
| ptp | fix PTP offset instability under heavy background multicast traffic; |
| ptp | fix PTP timestamps showing the wrong time on CRS510; |
| sfp | improve QSFP-DD breakout link establishing to NVIDIA DGX Spark and other devices; |
| system | improve stability; |
| user | improve failed login delay logic (CVE-2026-16347); |
| wifi | update radio regulatory information; |
| www | improve stability; |