MikroTik Changelogs

Search changelog entries

6.49.21 Stable 2026-Sep-03 (2 weeks ago)
Component Change
btest improve stability;
console improve stability;
fetch improve stability of the TFTP client;
snmp improve stability of SNMP;
ssh refactor SSH internal processes and improved system stability;
system improve stability;
system updated certificate for Windows executable signing;
timezone updated timezone information from "tzdata2026b" release;
7.25beta3 Development 2026-Sep-02 (2 weeks ago)
Component Change
app add the networkRouterIP variable for container apps;
app fix CHR apps getting stuck on "starting" on slower boards;
app show an error when an app variable cannot be resolved;
app update the environment variables of the docker-with-komodo app;
arm64 improved general system stability;
bgp add the always-compare-med setting;
bgp fix BGP link-local nexthops unreachable over a VRF and a crash when disabling an unnumbered connection;
bgp fix BGP unnumbered connections within a VRF;
bgp include the VNI number in outgoing EVPN routes;
bgp log failed BGP connection attempts;
bridge add dynamic ARP inspection;
bridge add IP source guard;
bridge add mlag-lacp-fallback and mlag-init-delay settings for MLAG;
bridge fix a false "already added as bridge port" error;
bridge fix an MLAG peer getting stuck in the disabled state after config changes;
bridge fix bridge ports not forwarding;
bridge fix MLAG failing to establish after bridge config changes;
bridge fix MLAG MAC handling when used with VRRP;
bridge fix unexpected MAC aging in MLAG after a MAC move;
bridge fix VRRP MAC behavior in MLAG setups;
bridge improve stability;
bridge make MVRP work with MLAG dual bonds;
bridge rename the IGMP last-member-interval property to last-member-query-interval;
btest improve stability;
bth add resumable file uploads;
bth allow file sharing over direct LAN connections;
bth check the available disk space before a file upload;
bth fix the file share getting stuck when disabling;
capsman add hw-protection-threshold;
capsman fix the last-ip value being shown backwards;
certificate allow importing a cross-signed certificate without overwriting the existing one;
certificate fix ACME certificate issuance for wildcard domains;
certificate fix changing the built-in trust store setting (introduced in 7.22.2);
certificate improve certificate import process;
certificate refactor certificate internal processes;
cloud improve stability of backup file downloads;
console allow the array access operator to accept arrays of indices or keys;
console expose globals in the API;
console fix a memory leak in background scripts;
console fix background ":execute as-string" jobs not terminating on interrupt;
console fix comment wrapping in the monitor command;
console fix inconsistent /ip/firewall/filter print with src-address-list and dst-address-list;
console fix the where filter ignoring flags set to false;
console improve export order;
console improve stability;
console prevent an out-of-memory condition when ":execute as-string" produces large output;
console prevent duplicate entries in /port/remote-access;
container add a Ctrl-] escape sequence to exit a stuck container shell;
container fix container interface handling on CHR;
container improve container image extraction;
container require the container device-mode to enable swap;
crypto fix a possible crash during IPsec processing on Qualcomm devices;
detnet use a single random source port;
dhcpv4-server add ipv6-only-preferred parameter to respect option 108;
dhcpv4-server show DHCP option 82 parameters in ASCII in addition to hex;
dhcpv6-client add option 39 with the client hostname;
dhcpv6-client fix DHCPv6 client address handling after prefix-hint changes;
dhcpv6-client remove a duplicate dhcp-options parameter;
dhcpv6-relay use the packet's source MAC for option 79 if relay and client are on the same link layer;
dhcpv6-server add option 39 (FQDN) support and add-dns-entries option;
disk improve RAID5/6 throughput;
disk improve stability of the SMB server;
dns improve stability;
dot1x improve stability;
dot1x rename the reauth-timeout to reauth-period;
email fix server certificate verification;
email show certificate related errors in the log;
ethernet add the arp-accept parameter for interfaces with MAC;
ethernet fix a stability issue on RB1100AHx2 under heavy traffic;
ethernet fix bogus fast-path Rx traffic reported on an unconnected ether8 port on RB5009;
ethernet fix link flap and unexpected reboots on RB5009;
ethernet fix PPPoE link flapping on Intel X710;
ethernet fix PPPoE over VLAN not working on Mellanox ConnectX-4;
ethernet fix SFP compatibility on E-series devices;
ethernet improve stability on Alpine devices after a switch reset;
ethernet improve stability on hAP be3 Media;
ethernet improve stability on x86 routers with Mellanox NICs;
evpn publish MAC-IP routes (RT-2) for neighbors;
fetch improve stability of the TFTP client;
fetch improve upload state reporting when using sftp;
fetch never set a cookie jar for HTTP requests;
fetch show a clearer error when keep-result and output are both used;
firewall add NAT-related fields to CEF format logging;
hardware show the device name and location in /system/resource/hardware menu;
igmp-proxy improve stability when changing /routing/igmp-proxy parameters;
iot add Bluetooth output power control;
iot allow a custom radio plan even under a regional lock;
iot enforce the fixed antenna gain on boards with an embedded antenna;
iot fix round-trip-time timing issues in LoRaWAN Basic Station;
ip-service fix services becoming unreachable after their VRF is disabled and re-enabled;
ipsec add XFRM interface support;
ipsec fix policy and SA handling after moving it to netlink;
ipsec improve IKE handshake stability;
ipsec improved service stability when processing an IKEv1 request;
ipv6 add a neighbor discovery ping;
ipv6 fix cases when address is lost after reboot if prefix was taken from pool;
ipv6 fix the DNS timer in router advertisements;
ipv6 ignore router advertisements received on interfaces not in the accepting list;
l3hw fix IPv6 link-local traffic being routed incorrectly;
leds add dark-mode support for L41;
leds fix LEDs set to interface status staying off when the interface is active;
log improve stability of logging;
lte accept both y and yes for eSIM confirmation;
lte add band display support for Huawei ME909s modems;
lte add missing network error messages for MBIM modems;
lte add support for supplementary downlink and uplink band only selection restriction;
lte add the sms-protocol=qmi option for sending and reading SMS;
lte use RA for IPv6 acquisition for FG621;
lte fixed multi-APN for R11l-LTE7 and R11e-LTE6 modems;
lte fix the RG650E-EU modem not bringing link up after a firmware update;
lte fix traffic statistics in MBIM passthrough mode;
lte remove leftover APN slave interfaces when the master LTE interface is removed;
lte rename "firmware-update" to "firmware-upgrade" in the show-capabilities command output;
lte fix the subscriber number not updating after switching SIM slots;
lte fixed support for MC7710 Sierra modem;
lte fixed IPv6 acquisition for R11e-LTE-US modem;
lte improved link recovery for R11l-LTE7 modem;
lte clear dhcp-server network in passthrough mode when the link goes down;
lte improved system stability when using passthrough mode;
mac-telnet improve stability of MAC Telnet sessions;
netinstall fix a duplicate device entry on RB2011 with SFP;
netinstall fix multiple active interfaces inheriting the first interface's settings;
netinstall fix Netinstall failing to reinstall RB850Gx2 devices;
netinstall fix Netinstaller's memory check failing downloads to disk;
ospf fix DR/BDR traffic not being received with multiple instances;
ospf improve stability when a neighbor is lost;
pim add MLD support for PIM;
pim fix duplicate PIM configuration parameters;
pim fix PIM-SM issues with IPv6;
pim fix wrong or missing PIM configuration by separating PIM and GMP per interface;
ping add parameter checks for arp ping;
poe-out fixed missing PoE-Out interface on hEX PoE lite, RB260GSP, OmniTIK 5 PoE, PowerBox;
port accumulate incoming data in log file even without TCP clients connected;
port add an FTDI latency_timer option for low-latency serial applications;
ppp add port interface info to PPP outbound channel defaults;
ppp fix a packet leak during dial-on-demand connection of a ppp-out interface;
ppp fix BG77 modem port name and channel count;
ppp fix the offline firmware-update notification for BG77/BG770 modems;
ppp fix the SINR value reported for BG77 and BG770 modems;
ptp add support for fixed master and slave port roles;
ptp add transparent clock mode;
qos fix PFC and lossless buffer issues (introduced in v7.23);
queue fix a typo in the cake-overhead-scheme parameter value;
reverse-proxy improve stability of the reverse proxy;
romon improve stability of RoMON;
route fix a nexthop mismatch;
routing improve stability of routing protocol packet handling;
sniffer improve packet time resolution;
snmp add an OID and logging for blacklisted program access;
snmp add CAPsMAN radio data to SNMP;
snmp add dynamic SNMP engine ID assignment;
snmp add interface table with mtu and l2mtu OIDs;
snmp add IP pool OIDs;
snmp add IPv6 address and interface name to the MNDP neighbour table;
snmp add OID blacklisting;
snmp add OIDs for Netwatch probes;
snmp add OSPF MIB tables;
snmp add SHA-2 authentication for SNMPv3;
snmp add transmit drop counters;
snmp add VRRP status OIDs for monitoring;
snmp fix the reported capability flags in LLDP-MIB;
snmp fix the snmp tools timing out when authentication is used;
snmp improve stability of SNMP;
snmp log a warning when the src-address family does not match the request;
snmp remove an interface OID that should not be accessible;
socks fix SOCKS proxy connection and address handling;
ssh add host key verification for the SSH client;
ssh limit server output to the client's window size;
ssh refactor SSH internal processes and improved system stability;
ssh show router host key fingerprint;
ssh switch the default host key type to Ed25519;
ssl enabled hardware accelerated GCM on Alpine CPUs;
ssl improve logging;
switch add packet and byte counters for ACL rules on Marvell Prestera switches;
switch fix degraded slow-path throughput on CRS304 switch (introduced in v7.22);
system fix memory handling and correctness issues in the core library;
system fix the frequency units from Mhz to MHz;
system improve stability;
system reduce the fan control interval on multi-core boards;
system remove the channel label from the RouterOS version;
system warn about a missing wifi driver package on BE boards;
tftp add VRF support;
tr069 improve stability;
traffic-flow improved system stability when disabling traffic flow on a busy system;
traffic-gen improve stability;
upnp improve stability;
usb improve stability of RNDIS data handling;
user fix removal of inactive REST API sessions (introduced in 7.21);
userman improve stability when importing database files;
vlan add a force-mac-address option for VLAN interfaces;
vrrp improve stability;
webfig add a generic table and union group support;
webfig add column resizing to embedded tables;
webfig hide the left menu only on QuickSet and Terminal pages;
webfig improve stability;
webfig update style;
webfig update the login page Help link;
wifi add a stream-port argument to configure the sniffer streaming server port;
wifi add fast transition support for MLD devices;
wifi add interworking, aaa and steering settings to the network configuration;
wifi add more steering debug logs;
wifi add network 'labels' parameter to WinBox and WebFig;
wifi do not preserve branding package on cap when upgrading via capsman;
wifi fix channel reselect interval/time operation for wifi-qcom-be and wifi-mediatek interfaces;
wifi fix incorrect scan results for 320 MHz access points;
wifi fix MLD link type change and SA query in station mode;
wifi fix SAE authentication using a wrong cached PMK;
wifi fix station statistics not updating after switching MLD links;
wifi fix the interworking network type;
wifi fix the wrong band shown in the registration table;
wifi improve stability;
wifi perform a channel switch instead of dropping clients on radar detection;
wifi preserve dude package on cap when upgrading via capsman;
wifi report channel in log messages;
wifi report management frame protection (MFP) usage in registration-table;
wifi show the EAP user identity in the registration table;
wifi show the MLD links and SSID in MLO client log messages;
wifi-mediatek improve MLO client reconnection;
wifi-qcom fix disconnects during fast transition roaming;
wifi-qcom fix station mode association failures;
wifi-qcom-ac fix a regression in station MAC address handling;
wifi-qcom-ac reduce package size;
wifi-qcom-be add hw-protection-mode support;
wifi-qcom-be add the distance setting for 802.11be devices;
wifi-qcom-be fix the block ack request being declined after a channel switch;
wifi-qcom-be fix Wi-Fi intermittently unavailable after reboot;
wifi-qcom-be improve throughput in dense client environments;
wifi-qcom-be upgrade driver and firmware;
winbox add a filtered LLDP tab to neighbor discovery;
winbox add a Security tab and reorganize bridge and port dialogs;
winbox add a wifi radio regulatory info (reg-info) view;
winbox add device-mode configuration;
winbox add ISIS support;
winbox add progress bar support to the GUI;
winbox add RSRP and RSRQ signal graphs to the PPP info view;
winbox add the client MTU option for WireGuard peers;
winbox add the container save option;
winbox add wifi Spectral Scan support;
winbox allow power-cycling multiple interfaces at once;
winbox allow tuple fields with more than two values and multiple separators;
winbox fix SFP optical power values of 0.0 dBm not being shown;
winbox fix the "addresses" spelling in read-only fields;
winbox fix the EC/IO signal quality graph;
winbox fix the ISIS neighbor level type being empty for "l2";
winbox fix the Memory Limit field of fq_codel to use bytes;
winbox fix the Min Prefix field in the routing rule dialog;
winbox fix the MPLS TE tunnel path hops field;
winbox fix the range field displayed in route filters;
winbox fix the Skins menu for user groups opening a non-existent window;
winbox fix the system note display on startup;
winbox fix the wifi Authentication Types and Encryption fields;
winbox improve stability of WinBox protocol handling;
winbox improve status reporting under Tools/Email menu;
winbox make the Power Cycle button act only on the selected interface;
winbox open the Format Drive panel only for supported disks;
winbox remove the redundant empty status field from the License window;
winbox rename "send" to "transmit" in the Bandwidth Test window;
winbox rework the switch QoS statistics table;
winbox show WireGuard peer information;
wireguard add the client-mtu parameter;
wireguard allow referencing a peer by its name;
wireguard allow unsetting the client-listen-port;
wireguard improve error message reporting when adding a new peer;
wireguard keep peer rx/tx counters when the peer is disabled and enabled;
wireguard use the MTU value when importing a configuration;
wireguard warn when an allowed-address overlaps another peer;
www add the remote client IP and domain to HTTPS log messages;
www fix a memory leak when parsing authentication headers;
www improve stability;
www improve URI parsing;
7.24.1 Stable 2026-Aug-21 (1 month ago)
Component Change
app fix entrypoint and cmd for opencloud-extended-collabora app;
bridge fix missing host "E" flag for CRS8xx series switches;
bridge fix MLAG for CRS8xx series switches;
bridge fix stability issue when using VRRP on bridge;
bridge improve MLAG host aging and deletion logic;
console fix "find" command argument lookup issue (introduced in v7.24);
container improve host isolation when container is set to "privileged=yes";
l3hw fix stability issue on IPv6 offload enable;
l3hw fix VRF offload on bond interface remove;
leds fix "interface-status" trigger;
snmp properly validate password length when applying configuration;
ssh refactor SSH service internal processes;
switch fix possible Rx traffic stall on CPU for devices with Marvell Prestera switch chip;
switch fix stability issue during L2 loop for 98DX224S, 98DX226S, 98DX2528, and 98DX3236 switch chips;
switch fix stability issue on RB3011 (introduced in v7.22);
system improve handling of invalid SSL/TLS requests;
wifi fix stability issue for hAP be lite;
wireguard fix peer disable/enable state handling, which could leave the tunnel non-functional (introduced in v7.24);
wireguard fix private key handling, including empty private keys;
www improve service responsiveness when receiving malformed packets;
7.24 Stable 2026-Aug-14 (1 month ago)
Component Change
adlist improved service stability when adjusting adlist configuration;
app added "HF_TOKEN" env to openwebui;
app added "network-outgoing-access" parameter which does not allow app to make outgoing connections;
app added hermes-agent, inventree, opencloud, opencloud-extended apps;
app added PAPERLESS_SECRET_KEY env to paperless-nginx;
app allow "reset" even if disk not configured;
app allow HTTP for Gitea when "check-certificate=no";
app allow setting "working_dir" in app YAML;
app changed pmacct-netflow YAML;
app disable UI in Hermes, access through /container/shell;
app fixed apps not updating firewall redirects when changed in YAML;
app fixed apps sometimes getting stuck on "waiting for layer";
app make secrets sensitive to avoid polluting configuration export;
app removed healthcheck from opencloud-extended-collabora;
app reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop;
app show CHR's address instead of the container's;
app use randomly generated secrets in new apps;
bgp fixed EVPN label corruption and corrected EVPN type-5 output;
bgp improved stability when receiving malformed packets;
bgp removed "save-to" from "resend" command;
bgp-vpn fixed blackhole route export;
bridge added "querier-uses-bridge-address" setting to use bridge source IP address for IGMP querier;
bridge added DHCPv4 snooping IP binding table;
bridge added scheduling point during VLAN processing to prevent soft lockups when flushing FDB over large VLAN ranges;
bridge fixed forwarding through peer-port after disabling MLAG;
bridge fixed local static host entries;
bridge fixed MLAG MAC address handling issues related to aging, flushing and moving;
bridge fixed stability issue when using DHCPv4 snooping;
bridge fixed stuck MLAG session when using mismatched L2MTU (introduced in v7.23);
bridge improved bridge and port STP "priority" setting (warn when a non-compliant value is used and allow selecting a value from a list);
bridge improved STP, BPDU and topology change handling with MLAG, ensure dual-connected port STP state is in sync with MLAG peer;
btest added VRF support for bandwidth-test and speed-test;
certificate added "acme-renew" command;
certificate general improvements in certificate handling;
certificate use AES encryption when exporting certificates in PKCS#12 format;
console added "days" to scheduler;
console added "in" and "has" operators for array types;
console added "order-by" parameter to "print" command, allowing sorting by up to three arguments in ascending or descending order;
console added comparison operators for array type;
console added log tracing when scripts fail to start due to permissions;
console do not terminate self-removing scripts;
console fixed "print follow on-event" script runner command not showing all argument values in some cases;
console fixed argument mappings in "do" block for monitor commands;
console fixed proplist order in monitor commands;
console fixed script import/export with empty "policy" setting;
console fixed stability issue in full-screen editor;
console fixed UTF-8 comparisons on some architectures;
console improved "print detail" mode;
console improved script handling and error logging when running scripts from external sources (e.g. DHCP, SNMP, Netwatch, etc.);
console make "mac-auth-password" sensitive in "/ip/hotspot/profile";
console make "password" sensitive in "/system/package/local-update/mirror";
console produce runtime errors for bad command parameters;
console prompt about and offer to stop already existing serial terminal session when opening new one;
console renamed "address" to "available-from" in "/ip/service" (backwards compatible via deprecation);
console renamed "reauth-timeout" to "reauth-period" in "/interface/dot1x/server" (backwards compatible via deprecation);
console restrict editing comments in WiFi registration table;
container added "save" command to allow saving container images;
container added "swap-current" usage;
container added "swap-max" global and per-container limit;
container added ability to run containers in privileged mode;
container added initial support for RKE2;
container do not allow starting with empty default DNS list and no DNS override;
container do not print environment variables in log on container startup;
container fixed "start-on-boot" not retrying on certain startup errors;
container fixed container "devices" override to appear under "/dev";
container improved layer size calculation to avoid potential loops;
container improved support for containers;
container reduced writes to flash when running health check;
container use env "TERM=xterm" if no TERM variable provided when running shell;
crypto fixed hardware accelerator for GCM cipher in TLS connection on Alpine CPUs;
defconf set "configuration.dtim-period=3" for WiFi;
defconf use "add-dns-entries=yes" on devices with DHCP server;
dhcp fixed processing of DHCP options that are longer than 255 bytes;
dhcpv4-relay fixed stability issue when creating duplicate relays;
dhcpv4-server do not reset "class-id" parameter when lease loses "bound" status;
dhcpv4-server set "ciaddr" in forcerenew messages so a relay, if used, can unicast such messages;
dhcpv6-relay fixed non-working relay when adding from WinBox;
dhcpv6-server fixed invalid flag;
discovery added "address6" column to default "/ip/neighbor" print view;
discovery added "discovery" logging topic;
discovery added "dying-gasp" feature for LLDP, MNDP, CDP that sends packet with "TTL=0" before graceful reboot/shutdown/upgrade;
discovery clear neighbor entry when receiving "dying-gasp" packet;
discovery improved service stability when sending discovery packets on interfaces that have hundreds of IP addresses;
disk added "last-seen" property that displays disk model and serial when removed;
disk added "raid-scrub-cancel" command;
disk added error message when disk state transitions from good to bad;
disk do not consider USB drives as self-encryption capable;
disk fixed "smart-info" not showing information on certain storage devices;
disk limited maximum swap size to be no more than 10x of device RAM;
disk resolved issue where storage device might change information upon reboot;
ethernet disable EEE on hAP be3 Media;
ethernet fixed stability issue for Chateau PRO ax devices;
ethernet fixed stability issue for devices with Alpine CPU;
ethernet removed "1G-baseT-half" link mode on RTL8367 switch;
fetch added "ip-type" parameter;
fetch added option to force HTTP/2 only (only for ARM64 and x86/CHR devices);
fetch fixed false "bad request" response when trying to fetch URL with IPv6 address in it;
fetch hint file list for "src-path" and "dst-path" parameters;
hardware renamed "max-power" to "manufacturer-reported-max-power";
iot added LoRa keep alive logic for UDP protocol;
iot added missing LoRa US radio plans;
iot added Wiliot USB dongle support;
iot allow maximum Modbus "timeout" property to be 10 seconds;
iot monitor LoRa worker state (watchdog);
iot pass Wiliot certification;
ip-service remove reverse-proxy for SMIPS;
ip-service show service name for "l2tp";
ipsec fixed expired SA handling to prevent “no such item” errors during listing;
ipsec,ike1 dropped base mode exchange;
ipsec,ike1 fixed negotiated PFS validation;
ipsec,ike1 improved SA, transform, fragment parsing and malformed packet validation;
ipsec,ike2 fixed ppk child key generation during rekey;
ipsec,ike2 improved KE generation validation during initial setup and child SA creation;
ipsec,ike2 improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA task;
ipsec,ike2 use first child KE selection only during IKE_AUTH exchange;
ipsec,qkd moved QKD to "/system/keymat-provider" menu and made it a generic key material provider;
ipv6 added "status" column to default "/ipv6/neighbor" print view;
ipv6,ra changed default "router-advertisement-route-distance" to 1;
ipv6,ra correctly process RAs advertising previously expired prefix;
ipv6,ra fixed prefix invalidation;
ipv6,ra use lowest value between IPv6/Pool and IPv6/ND/Prefix/Default as dynamic prefix lifetime;
isis fixed ECMP route removal;
l2tp allow fragmentation of large IPv6 packets;
l3hw added HW offloaded support for VLAN interfaces created directly on Ethernet for CRS8xx series switches;
l3hw added HW offloaded VRF support on 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98CX8410 switches;
l3hw added VRF assignment via switch ACL rules for devices with Marvell Prestera switch chip;
l3hw allow VLAN tagged traffic inside VXLAN tunnel;
l3hw fixed VRF-related issues for CRS8xx series switches;
l3hw fixed VTEP offload on IPv4 /32 route changes;
leds added dark mode support for L009, hAP ax2, hAP ax3, hEX refresh, hEX S (2025), hAP ax S and Chateau ax devices;
leds fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23);
leds improved interface stats activity for devices with Marvell Prestera switch chip;
lte added force-confirmation parameter for eSIM provision command;
lte cap IPv6 prefix lifetime for ipv6-interface;
lte do not add extra /128 IPv6 address for ipv6-interface;
lte do not query 5G neighbor cell info until RG650E-EU FW fixed;
lte enabled AT registration unsolicited event reporting for EG25-G and EC25-EU boards;
lte fixed cases where R11l-LTE7 modem would not display correct cell info after handover;
lte fixed EC/IO scale in CLI and GUI;
lte fixed EC25-EU, EG25-G traffic to 67 UDP;
lte fixed IPv6 RA handling for multiapn non-primary interface;
lte fixed third-party modems ICCID decoding for eSIM;
lte improved Cinterion PLS8-E roaming;
lte improved deregistration handling for AT modems;
lte improved system stability when no APN specified;
lte improved USB mode handling for BG770A-GL;
lte limit IPv6 prefix lifetime only when lifetime is advertised as infinity;
lte make modem MAC persistent for R11e-LTE6 and R11l-LTE7 modems;
lte remove site local DNS for ipv6-interface;
lte removed extra restart after firmware upgrade for EC200A-EU modem;
lte report short cell ID in 3G network mode also for AT modems;
lte restrict incoming calls for FG621-EU;
lte show "+CME ERROR: 10" as "SIM not present";
lte show "data-class" in LTE monitor instead of "access-technology" also for 5G AT modems;
lte show "primary-band" instead of "earfcn" in LTE monitor also for modems without CA support;
lte show RSCP and EC/IO parameter in 3G network mode for R11e-LTE6, R11l-LTE7 and FG621-EA modems;
mesh fixed missing FDB entries from wireless ports;
mpls added ICMP time exceeded handler for IPv6;
mpls make FastPath work with expl-null;
netinstall added Netinstall package;
netinstall improved architecture detection;
netinstall-cli added "help" parameter;
netinstall-cli added "reboot" and "shutdown" flags to control reboot after installation;
netwatch fixed an issue with DNS probe "timeout" parameter;
netwatch fixed HTTP GET probe over IPv6;
netwatch fixed inaccurate "rtt-stdev" value;
netwatch fixed issue where ICMP probes did not accept TTL exceeded packets when "accept-icmp-time-exceeded" was enabled;
netwatch increased maximum packet size to 65535;
ospf fixed stability issue during interface flaps;
ospf force passive for VRF interface;
pimsm make "hash-mask-length" parameter naming consistent and fixed typos;
poe-in added PoE-in monitoring and LLDP-based PoE negotiation support for newer devices (e.g. CRS504, CRS510, hEX S 2025, hAP be3 Media);
poe-out firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
poe-out firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
ppp added "MT-Address-List" to IPv6 address list when received from RADIUS and using DHCP for IPv6 configuration;
ppp added iccid field to ppp info command for BG77 and BG770 modems;
ppp always show current FW version when running firmware-upgrade;
ppp disable/enable modem radio state depending on ppp interface state;
ppp fixed cases where BG77 or BG770 firmware upgrade was not available;
ppp fixed ppp-out stability issue;
ppp get IPv6 configuration via RA for modems using PPP emulation mode;
ppp improved "info" command for BG77 and BG770 modems;
ppp improved OVPN underlying SSL connection management;
ppp only show pin in export with "show-sensitive" flag;
ppp report actual network data usage statistics instead of "0" for all IPv6 RADIUS accounting parameters on accounting "Stop" packet;
ppp toggle radio state on interface disable/enable;
queue fixed "undo" command for simple queues;
reverse-proxy improved stability;
rip do not export authentication keys by default;
route allow to add route with link-local destination address;
route fixed memory leak when flapping addresses or interfaces with routing protocols running;
route fixed potential race condition;
route respect the "interface" property when pinging IPv6 addresses over ECMP;
sfp fixed linking for hAP ax S and hEX S (2025) with "1G-baseX" link-mode;
sfp removed unsupported "2.5G-baseX" speed on CRS312-4C+8XG and CRS326-4C+20G+2Q+;
sftp fixed branding package upload;
sms added some GSM7 symbols to SMS tool;
snmp added hotspot active-user-count and host-count OIDs to MIKROTIK-MIB;
snmp added missing SFP OIDs to MIKROTIK-MIB;
snmp added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIB;
ssh added mlkem768x25519-sha256 key exchange support;
ssh do not attempt automatic empty password login when RADIUS is used;
ssh fixed SSH tunnel with IPv6 link-local address on non-ethernet interfaces;
ssh make SSH packet validation more strict;
supout added interface monitor-traffic;
supout added LTE eSIM section;
switch fixed IEEE reserved MAC handling for CRS1xx, CRS2xx switches;
system improved stability;
system renamed "factory-software" to "minimum-version" and "factory-firmware" to "minimum-firmware";
system restrict RouterOS processes using swap;
system show who is using "/system serial-terminal";
traffic-generator fixed injecting pcap/pcapng files on MIPSBE architecture;
tunnel fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22);
upgrade removed sensitive policy for "apply-changes" command;
usb allow overriding the power-reset duration;
usb fixed USB Ethernet interface default-name;
vpls added transmit loop detection;
vrrp added "v3-checksum-as-v2" setting;
vrrp fixed stability issue when "sync-connection-tracking" is enabled;
vxlan fixed missing L2MTU property when VRF is specified;
vxlan ignore disabled interfaces when checking for configuration conflicts;
webfig fixed issue with increasing keep-alive traffic;
webfig improved underlying encryption and stability processing;
webfig improvements to graphs;
wifi added "Preamble Puncturing" under "WiFi/Channel" menu;
wifi added dash when CAPsMAN generates interface name and prefix ends with digit;
wifi improved roaming/steering behavior for WiFi 7 MLO;
wifi improved stability;
wifi improved station-bridge mode;
wifi updated radio regulatory information;
wifi upgraded wifi-qcom driver;
wifi-mediatek fixed broken interfaces on startup;
wifi-mediatek fixed some channel definitions for certain countries;
wifi-mediatek improved channel switching;
wifi-mediatek improved stability during MLO channel switching;
winbox added "Network" configuration menu for WiFi;
winbox added "Preferred Architecture" setting for L009;
winbox added "SIM PIN" under "Tools/SMS";
winbox fixed "Connection Bytes" field under "IP/Firewall" menu;
winbox fixed "EC/IO" scaling for LTE interface;
winbox fixed "Use Ipsec" and "Ipsec Secret" under "Interfaces/L2TP Ether" menu;
winbox fixed empty value in "Immediate Gateway" under "IP/Routes" menu;
winbox fixed sort for "Address List" under "IPv6/Firewall" menu;
winbox make LoRa "Auth key" and MQTT "Password" sensitive;
winbox move "EAP" under "Security" tab for WiFi;
winbox show "Any. Port" column by default under "IP/Firewall" menu;
winbox show preferred and valid lifetime of IPv6 address also on static IPs;
winbox show priority bits in "VLAN ID" field under "Tools/Packet Sniffer" menu;
wireguard added support for domain names in client-dns;
wireguard added warning when allowed-address overlaps with another peer on the same interface;
wireguard fixed peer recreation on interface change;
wireguard fixed peer Tx/Rx counters;
wireguard fixed wg-export comments output and case when endpoint is not set;
wireguard fixed whitespace handling in AllowedIPs during wg-import;
wireguard generate port number when specified as zero;
wireguard improved wg-export to print endpoint domain name;
wireguard improved wg-import to quietly ignore wg-quick specific keys;
wireguard reconfigure peer only when meaningful changes are detected;
wireguard reinitialize socket on VRF change;
x86 fixed IRQ displaying per CPU on Intel 700 series NIC;
7.24rc4 Testing 2026-Aug-11 (1 month ago)
Component Change
app added PAPERLESS_SECRET_KEY env to paperless-nginx;
app disable UI in Hermes, access through /container/shell;
app reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop;
ethernet disable EEE on hAP be3 Media;
ip improved stability for reverse-proxy (additional fixes);
ipsec fixed expired SA handling to prevent “no such item” errors during listing;
ipsec,ike1 dropped base mode exchange;
ipsec,ike1 improved SA, transform, fragment parsing and malformed packet validation;
ipsec,ike2 fixed ppk child key generation during rekey;
ipsec,ike2 use first child KE selection only during IKE_AUTH exchange;
leds fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23);
poe-out fixed possible PoE-out configuration loss on certain devices (introduced in v7.24beta1);
switch fixed default L2MTU drift for devices with QCA8337, Atheros8327 switch (introduced in v7.24beta2);
system improved stability;
usb allow overriding the power-reset duration;
wifi updated radio regulatory information (additional fixes);
wireguard fixed peer Tx/Rx counters;
wireguard generate port number when specified as zero;
wireguard reinitialize socket on VRF change;