Get notified when new firmware is released for this device.
Firmware History
7.23.5 (long-term)
LatestSecurity
The 7.23.4 release was an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give you time to update your systems, we are not publishing detailed information yet. This release, 7.23.5, additionally addresses an urgent issue introduced in 7.23.4.
*) dhcp - fixed IPv6 DHCP functionality (introduced in v7.23.4);
Router firmware is critical for network security. Updates patch vulnerabilities that could allow remote access to your network, fix Wi-Fi stability issues, improve throughput performance, and add new features. Given that routers are internet-facing devices, keeping firmware current is one of the most important security measures you can take.
This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information.
*) bgp - fix BGP link-local nexthops unreachable over a VRF and a crash when disabling an unnumbered connection;
*) btest - improve stability;
*) certificate - fix changing the built-in trust store setting (introduced in 7.22.2);
*) console - improve stability;
*) dhcp - improve stability of DHCP handling;
*) disk - improve stability of the SMB server;
*) fetch - improve stability of the TFTP client;
*) ipsec - fixed expired SA handling to prevent "no such item" errors during listing;
*) ipsec - improve IKE handshake stability;
*) leds - improved interface stats activity for devices with Marvell Prestera switch chip;
*) lte - removed extra restart after firmware upgrade for EC200A-EU modem;
*) lte - fix the RG650E-EU modem not bringing link up after a firmware update;
*) ping - add parameter checks for arp ping;
*) snmp - properly validate password length when applying configuration;
*) ssh - refactor SSH internal processes and improved system stability;
*) system - improve handling of invalid SSL/TLS requests;
*) system - improve stability;
*) tunnel - fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22);
*) webfig - improve stability;
*) wifi - updated radio regulatory information;
*) winbox - fix the "addresses" spelling in read-only fields;
*) wireguard - fixed peer Tx/Rx counters;
*) wireguard - generate port number when specified as zero;
*) wireguard - reinitialize socket on VRF change;
*) www - improve stability;
This is an important security update. Most configurations are not at risk, but upgrading is highly recommended. To give time to update your systems, we are not currently publishing detailed information.
*) bgp - fix BGP link-local nexthops unreachable over a VRF and a crash when disabling an unnumbered connection;
*) btest - improve stability;
*) certificate - fix changing the built-in trust store setting (introduced in 7.22.2);
*) console - fix a memory leak in background scripts;
*) console - improve stability;
*) container - improve container image extraction;
*) dhcp - improve stability of DHCP handling;
*) disk - improve stability of the SMB server;
*) ethernet - improve stability on hAP be3 Media;
*) fetch - improve stability of the TFTP client;
*) ipv6 - add a neighbor discovery ping;
*) leds - fix LEDs set to interface status staying off when the interface is active;
*) lte - fix the RG650E-EU modem not bringing link up after a firmware update;
*) ping - add parameter checks for arp ping;
*) poe-out - fixed missing PoE-Out interface on hEX PoE lite, RB260GSP, OmniTIK 5 PoE, PowerBox;
*) ssh - refactor SSH internal processes and improved system stability;
*) system - improve stability;
*) webfig - improve stability;
*) winbox - fix the "addresses" spelling in read-only fields;
*) www - improve stability;
*) adlist - improved service stability when adjusting adlist configuration;
*) app - added "HF_TOKEN" env to openwebui;
*) app - added "network-outgoing-access" parameter which does not allow app to make outgoing connections;
*) app - added hermes-agent, inventree, opencloud, opencloud-extended apps;
*) app - added PAPERLESS_SECRET_KEY env to paperless-nginx;
*) app - allow "reset" even if disk not configured;
*) app - allow HTTP for Gitea when "check-certificate=no";
*) app - allow setting "working_dir" in app YAML;
*) app - changed pmacct-netflow YAML;
*) app - disable UI in Hermes, access through /container/shell;
*) app - fixed apps not updating firewall redirects when changed in YAML;
*) app - fixed apps sometimes getting stuck on "waiting for layer";
*) app - make secrets sensitive to avoid polluting configuration export;
*) app - removed healthcheck from opencloud-extended-collabora;
*) app - reserve the app's VETH IP when stopped to eliminate IP address changes on every start/stop;
*) app - show CHR's address instead of the container's;
*) app - use randomly generated secrets in new apps;
*) bgp - fixed EVPN label corruption and corrected EVPN type-5 output;
*) bgp - improved stability when receiving malformed packets;
*) bgp - removed "save-to" from "resend" command;
*) bgp-vpn - fixed blackhole route export;
*) bridge - added "querier-uses-bridge-address" setting to use bridge source IP address for IGMP querier;
*) bridge - added DHCPv4 snooping IP binding table;
*) bridge - added scheduling point during VLAN processing to prevent soft lockups when flushing FDB over large VLAN ranges;
*) bridge - fixed forwarding through peer-port after disabling MLAG;
*) bridge - fixed local static host entries;
*) bridge - fixed MLAG MAC address handling issues related to aging, flushing and moving;
*) bridge - fixed stability issue when using DHCPv4 snooping;
*) bridge - fixed stuck MLAG session when using mismatched L2MTU (introduced in v7.23);
*) bridge - improved bridge and port STP "priority" setting (warn when a non-compliant value is used and allow selecting a value from a list);
*) bridge - improved STP, BPDU and topology change handling with MLAG, ensure dual-connected port STP state is in sync with MLAG peer;
*) btest - added VRF support for bandwidth-test and speed-test;
*) certificate - added "acme-renew" command;
*) certificate - general improvements in certificate handling;
*) certificate - use AES encryption when exporting certificates in PKCS#12 format;
*) console - added "days" to scheduler;
*) console - added "in" and "has" operators for array types;
*) console - added "order-by" parameter to "print" command, allowing sorting by up to three arguments in ascending or descending order;
*) console - added comparison operators for array type;
*) console - added log tracing when scripts fail to start due to permissions;
*) console - do not terminate self-removing scripts;
*) console - fixed "print follow on-event" script runner command not showing all argument values in some cases;
*) console - fixed argument mappings in "do" block for monitor commands;
*) console - fixed proplist order in monitor commands;
*) console - fixed script import/export with empty "policy" setting;
*) console - fixed stability issue in full-screen editor;
*) console - fixed UTF-8 comparisons on some architectures;
*) console - improved "print detail" mode;
*) console - improved script handling and error logging when running scripts from external sources (e.g. DHCP, SNMP, Netwatch, etc.);
*) console - make "mac-auth-password" sensitive in "/ip/hotspot/profile";
*) console - make "password" sensitive in "/system/package/local-update/mirror";
*) console - produce runtime errors for bad command parameters;
*) console - prompt about and offer to stop already existing serial terminal session when opening new one;
*) console - renamed "address" to "available-from" in "/ip/service" (backwards compatible via deprecation);
*) console - renamed "reauth-timeout" to "reauth-period" in "/interface/dot1x/server" (backwards compatible via deprecation);
*) console - restrict editing comments in WiFi registration table;
*) container - added "save" command to allow saving container images;
*) container - added "swap-current" usage;
*) container - added "swap-max" global and per-container limit;
*) container - added ability to run containers in privileged mode;
*) container - added initial support for RKE2;
*) container - do not allow starting with empty default DNS list and no DNS override;
*) container - do not print environment variables in log on container startup;
*) container - fixed "start-on-boot" not retrying on certain startup errors;
*) container - fixed container "devices" override to appear under "/dev";
*) container - improved layer size calculation to avoid potential loops;
*) container - improved support for containers;
*) container - reduced writes to flash when running health check;
*) container - use env "TERM=xterm" if no TERM variable provided when running shell;
*) crypto - fixed hardware accelerator for GCM cipher in TLS connection on Alpine CPUs;
*) defconf - set "configuration.dtim-period=3" for WiFi;
*) defconf - use "add-dns-entries=yes" on devices with DHCP server;
*) dhcp - fixed processing of DHCP options that are longer than 255 bytes;
*) dhcpv4-relay - fixed stability issue when creating duplicate relays;
*) dhcpv4-server - do not reset "class-id" parameter when lease loses "bound" status;
*) dhcpv4-server - set "ciaddr" in forcerenew messages so a relay, if used, can unicast such messages;
*) dhcpv6-relay - fixed non-working relay when adding from WinBox;
*) dhcpv6-server - fixed invalid flag;
*) discovery - added "address6" column to default "/ip/neighbor" print view;
*) discovery - added "discovery" logging topic;
*) discovery - added "dying-gasp" feature for LLDP, MNDP, CDP that sends packet with "TTL=0" before graceful reboot/shutdown/upgrade;
*) discovery - clear neighbor entry when receiving "dying-gasp" packet;
*) discovery - improved service stability when sending discovery packets on interfaces that have hundreds of IP addresses;
*) disk - added "last-seen" property that displays disk model and serial when removed;
*) disk - added "raid-scrub-cancel" command;
*) disk - added error message when disk state transitions from good to bad;
*) disk - do not consider USB drives as self-encryption capable;
*) disk - fixed "smart-info" not showing information on certain storage devices;
*) disk - limited maximum swap size to be no more than 10x of device RAM;
*) disk - resolved issue where storage device might change information upon reboot;
*) ethernet - disable EEE on hAP be3 Media;
*) ethernet - fixed stability issue for Chateau PRO ax devices;
*) ethernet - fixed stability issue for devices with Alpine CPU;
*) ethernet - removed "1G-baseT-half" link mode on RTL8367 switch;
*) fetch - added "ip-type" parameter;
*) fetch - added option to force HTTP/2 only (only for ARM64 and x86/CHR devices);
*) fetch - fixed false "bad request" response when trying to fetch URL with IPv6 address in it;
*) fetch - hint file list for "src-path" and "dst-path" parameters;
*) hardware - renamed "max-power" to "manufacturer-reported-max-power";
*) iot - added LoRa keep alive logic for UDP protocol;
*) iot - added missing LoRa US radio plans;
*) iot - added Wiliot USB dongle support;
*) iot - allow maximum Modbus "timeout" property to be 10 seconds;
*) iot - monitor LoRa worker state (watchdog);
*) iot - pass Wiliot certification;
*) ip-service - remove reverse-proxy for SMIPS;
*) ip-service - show service name for "l2tp";
*) ipsec - fixed expired SA handling to prevent “no such item” errors during listing;
*) ipsec,ike1 - dropped base mode exchange;
*) ipsec,ike1 - fixed negotiated PFS validation;
*) ipsec,ike1 - improved SA, transform, fragment parsing and malformed packet validation;
*) ipsec,ike2 - fixed ppk child key generation during rekey;
*) ipsec,ike2 - improved KE generation validation during initial setup and child SA creation;
*) ipsec,ike2 - improved PPK handling by always using it when authorized, including additional Child SAs, and moved PPK processing to the Child SA task;
*) ipsec,ike2 - use first child KE selection only during IKE_AUTH exchange;
*) ipsec,qkd - moved QKD to "/system/keymat-provider" menu and made it a generic key material provider;
*) ipv6 - added "status" column to default "/ipv6/neighbor" print view;
*) ipv6,ra - changed default "router-advertisement-route-distance" to 1;
*) ipv6,ra - correctly process RAs advertising previously expired prefix;
*) ipv6,ra - fixed prefix invalidation;
*) ipv6,ra - use lowest value between IPv6/Pool and IPv6/ND/Prefix/Default as dynamic prefix lifetime;
*) isis - fixed ECMP route removal;
*) l2tp - allow fragmentation of large IPv6 packets;
*) l3hw - added HW offloaded support for VLAN interfaces created directly on Ethernet for CRS8xx series switches;
*) l3hw - added HW offloaded VRF support on 98DX8208, 98DX8216, 98DX8212, 98DX8332, 98DX3257, 98DX4310, 98DX8525, 98DX3255, 98CX8410 switches;
*) l3hw - added VRF assignment via switch ACL rules for devices with Marvell Prestera switch chip;
*) l3hw - allow VLAN tagged traffic inside VXLAN tunnel;
*) l3hw - fixed VRF-related issues for CRS8xx series switches;
*) l3hw - fixed VTEP offload on IPv4 /32 route changes;
*) leds - added dark mode support for L009, hAP ax2, hAP ax3, hEX refresh, hEX S (2025), hAP ax S and Chateau ax devices;
*) leds - fixed Ethernet activity LED for Chateau LTE18 ax (introduced in v7.23);
*) leds - improved interface stats activity for devices with Marvell Prestera switch chip;
*) lte - added force-confirmation parameter for eSIM provision command;
*) lte - cap IPv6 prefix lifetime for ipv6-interface;
*) lte - do not add extra /128 IPv6 address for ipv6-interface;
*) lte - do not query 5G neighbor cell info until RG650E-EU FW fixed;
*) lte - enabled AT registration unsolicited event reporting for EG25-G and EC25-EU boards;
*) lte - fixed cases where R11l-LTE7 modem would not display correct cell info after handover;
*) lte - fixed EC/IO scale in CLI and GUI;
*) lte - fixed EC25-EU, EG25-G traffic to 67 UDP;
*) lte - fixed IPv6 RA handling for multiapn non-primary interface;
*) lte - fixed third-party modems ICCID decoding for eSIM;
*) lte - improved Cinterion PLS8-E roaming;
*) lte - improved deregistration handling for AT modems;
*) lte - improved system stability when no APN specified;
*) lte - improved USB mode handling for BG770A-GL;
*) lte - limit IPv6 prefix lifetime only when lifetime is advertised as infinity;
*) lte - make modem MAC persistent for R11e-LTE6 and R11l-LTE7 modems;
*) lte - remove site local DNS for ipv6-interface;
*) lte - removed extra restart after firmware upgrade for EC200A-EU modem;
*) lte - report short cell ID in 3G network mode also for AT modems;
*) lte - restrict incoming calls for FG621-EU;
*) lte - show "+CME ERROR: 10" as "SIM not present";
*) lte - show "data-class" in LTE monitor instead of "access-technology" also for 5G AT modems;
*) lte - show "primary-band" instead of "earfcn" in LTE monitor also for modems without CA support;
*) lte - show RSCP and EC/IO parameter in 3G network mode for R11e-LTE6, R11l-LTE7 and FG621-EA modems;
*) mesh - fixed missing FDB entries from wireless ports;
*) mpls - added ICMP time exceeded handler for IPv6;
*) mpls - make FastPath work with expl-null;
*) netinstall - added Netinstall package;
*) netinstall - improved architecture detection;
*) netinstall-cli - added "help" parameter;
*) netinstall-cli - added "reboot" and "shutdown" flags to control reboot after installation;
*) netwatch - fixed an issue with DNS probe "timeout" parameter;
*) netwatch - fixed HTTP GET probe over IPv6;
*) netwatch - fixed inaccurate "rtt-stdev" value;
*) netwatch - fixed issue where ICMP probes did not accept TTL exceeded packets when "accept-icmp-time-exceeded" was enabled;
*) netwatch - increased maximum packet size to 65535;
*) ospf - fixed stability issue during interface flaps;
*) ospf - force passive for VRF interface;
*) pimsm - make "hash-mask-length" parameter naming consistent and fixed typos;
*) poe-in - added PoE-in monitoring and LLDP-based PoE negotiation support for newer devices (e.g. CRS504, CRS510, hEX S 2025, hAP be3 Media);
*) poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) ppp - added "MT-Address-List" to IPv6 address list when received from RADIUS and using DHCP for IPv6 configuration;
*) ppp - added iccid field to ppp info command for BG77 and BG770 modems;
*) ppp - always show current FW version when running firmware-upgrade;
*) ppp - disable/enable modem radio state depending on ppp interface state;
*) ppp - fixed cases where BG77 or BG770 firmware upgrade was not available;
*) ppp - fixed ppp-out stability issue;
*) ppp - get IPv6 configuration via RA for modems using PPP emulation mode;
*) ppp - improved "info" command for BG77 and BG770 modems;
*) ppp - improved OVPN underlying SSL connection management;
*) ppp - only show pin in export with "show-sensitive" flag;
*) ppp - report actual network data usage statistics instead of "0" for all IPv6 RADIUS accounting parameters on accounting "Stop" packet;
*) ppp - toggle radio state on interface disable/enable;
*) queue - fixed "undo" command for simple queues;
*) reverse-proxy - improved stability;
*) rip - do not export authentication keys by default;
*) route - allow to add route with link-local destination address;
*) route - fixed memory leak when flapping addresses or interfaces with routing protocols running;
*) route - fixed potential race condition;
*) route - respect the "interface" property when pinging IPv6 addresses over ECMP;
*) sfp - fixed linking for hAP ax S and hEX S (2025) with "1G-baseX" link-mode;
*) sfp - removed unsupported "2.5G-baseX" speed on CRS312-4C+8XG and CRS326-4C+20G+2Q+;
*) sftp - fixed branding package upload;
*) sms - added some GSM7 symbols to SMS tool;
*) snmp - added hotspot active-user-count and host-count OIDs to MIKROTIK-MIB;
*) snmp - added missing SFP OIDs to MIKROTIK-MIB;
*) snmp - added WiFi current channel "mtxrWifiInterfacesCurrentChannel" OID to MIKROTIK-MIB;
*) ssh - added mlkem768x25519-sha256 key exchange support;
*) ssh - do not attempt automatic empty password login when RADIUS is used;
*) ssh - fixed SSH tunnel with IPv6 link-local address on non-ethernet interfaces;
*) ssh - make SSH packet validation more strict;
*) supout - added interface monitor-traffic;
*) supout - added LTE eSIM section;
*) switch - fixed IEEE reserved MAC handling for CRS1xx, CRS2xx switches;
*) system - improved stability;
*) system - renamed "factory-software" to "minimum-version" and "factory-firmware" to "minimum-firmware";
*) system - restrict RouterOS processes using swap;
*) system - show who is using "/system serial-terminal";
*) traffic-generator - fixed injecting pcap/pcapng files on MIPSBE architecture;
*) tunnel - fixed stability issue caused by a misconfigured routing loop under bridge (introduced in v7.22);
*) upgrade - removed sensitive policy for "apply-changes" command;
*) usb - allow overriding the power-reset duration;
*) usb - fixed USB Ethernet interface default-name;
*) vpls - added transmit loop detection;
*) vrrp - added "v3-checksum-as-v2" setting;
*) vrrp - fixed stability issue when "sync-connection-tracking" is enabled;
*) vxlan - fixed missing L2MTU property when VRF is specified;
*) vxlan - ignore disabled interfaces when checking for configuration conflicts;
*) webfig - fixed issue with increasing keep-alive traffic;
*) webfig - improved underlying encryption and stability processing;
*) webfig - improvements to graphs;
*) wifi - added "Preamble Puncturing" under "WiFi/Channel" menu;
*) wifi - added dash when CAPsMAN generates interface name and prefix ends with digit;
*) wifi - improved roaming/steering behavior for WiFi 7 MLO;
*) wifi - improved stability;
*) wifi - improved station-bridge mode;
*) wifi - updated radio regulatory information;
*) wifi - upgraded wifi-qcom driver;
*) wifi-mediatek - fixed broken interfaces on startup;
*) wifi-mediatek - fixed some channel definitions for certain countries;
*) wifi-mediatek - improved channel switching;
*) wifi-mediatek - improved stability during MLO channel switching;
*) winbox - added "Network" configuration menu for WiFi;
*) winbox - added "Preferred Architecture" setting for L009;
*) winbox - added "SIM PIN" under "Tools/SMS";
*) winbox - fixed "Connection Bytes" field under "IP/Firewall" menu;
*) winbox - fixed "EC/IO" scaling for LTE interface;
*) winbox - fixed "Use Ipsec" and "Ipsec Secret" under "Interfaces/L2TP Ether" menu;
*) winbox - fixed empty value in "Immediate Gateway" under "IP/Routes" menu;
*) winbox - fixed sort for "Address List" under "IPv6/Firewall" menu;
*) winbox - make LoRa "Auth key" and MQTT "Password" sensitive;
*) winbox - move "EAP" under "Security" tab for WiFi;
*) winbox - show "Any. Port" column by default under "IP/Firewall" menu;
*) winbox - show preferred and valid lifetime of IPv6 address also on static IPs;
*) winbox - show priority bits in "VLAN ID" field under "Tools/Packet Sniffer" menu;
*) wireguard - added support for domain names in client-dns;
*) wireguard - added warning when allowed-address overlaps with another peer on the same interface;
*) wireguard - fixed peer recreation on interface change;
*) wireguard - fixed peer Tx/Rx counters;
*) wireguard - fixed wg-export comments output and case when endpoint is not set;
*) wireguard - fixed whitespace handling in AllowedIPs during wg-import;
*) wireguard - generate port number when specified as zero;
*) wireguard - improved wg-export to print endpoint domain name;
*) wireguard - improved wg-import to quietly ignore wg-quick specific keys;
*) wireguard - reconfigure peer only when meaningful changes are detected;
*) wireguard - reinitialize socket on VRF change;
*) x86 - fixed IRQ displaying per CPU on Intel 700 series NIC;
*) certificate - added "ISRG Root X2", "Root YE" and "Root YR" to SMIPS built-in root certificate authorities store;
*) certificate - added "Root YE" and "Root YR" to built-in root certificate authorities store;
*) defconf - added virtual "iot-wifi" to MLO supporting devices;
*) dhcpv4-server - fixed "expires-after" field for disabled static lease (introduced in v7.23);
*) fastpath - properly fall back to SlowPath when FastPath is not possible due to fragmentation;
*) ipsec - fixed identity lookup to skip past disabled and certificate-matched identities when scanning for an exact ID match;
*) ipsec,ike2 - improved logging when remote ID is specified;
*) ipsec,ike2 - use peer certificates also when identity has one set for peer matching;
*) ipv6,ra - show warning about paused automatic RA on upgraded routers;
*) ospf - fixed "duplicate config" issue when using ptp-unnumbered interface type;
*) ptp - fixed a race condition when reading transmit timestamps, which could cause unstable clock offset under background traffic;
*) ptp - fixed PTPv1 traffic forwarding when a PTPv2 profile is enabled on bridge ports;
*) snmp - improved SNMPv3 request processing logic;
*) system - added microSD card support for hAP be3 Media;
*) system - improved handling of data re-sending on authorization requests (introduced in v7.22);
*) system - improved stability;
*) system - updated certificate for Windows executable signing;
*) tftp - limit maximum simultaneous session count to 100;
!) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;
*) bfd - fixed delay on session print;
*) bgp - fixed advertisement print handling by "dst" when destination is in VRF;
*) bgp - fixed IPv6 End-of-Route processing;
*) bgp - improved stability on MP (multiprotocol) parsing;
*) bridge - fixed dynamic VLAN update for wifi interfaces;
*) bridge - fixed stability issue when using DHCPv4 snooping;
*) cloud - cloud backup file management now requires "policy" policy;
*) console - fixed unresponsiveness when entering safe-mode through the Windows 11 terminal;
*) container - fixed missing config.json issue when upgrading from version 7.20.8 or older;
*) disk - avoid reading SCSI stats all the time to allow disks to go to sleep;
*) ethernet - fixed stability issue with TSO on Alpine CPUs;
*) ethernet - improved system stability on devices with Alpine CPUs;
*) ipv6 - do not disable IPv6 FastPath when Traffic Flow is enabled;
*) isis - allow to configure metric-type;
*) isis - fixed missing "l2.lsp-refresh-interval" parameter;
*) l3hw - improved system stability on device shutdown/reboot;
*) lte - fixed cases where EC25-EU and EG25-G boards would receive packets with missing last 4 bytes;
*) lte - fixed crash on LTE passthrough interface deactivation;
*) ospf - fixed interface passive flag update in WinBox;
*) route - fixed static route flag handling by WinBox on disable;
*) route - removed deprecated "/routing/route/rule" menu;
*) switch - fixed issue with MAC table for RB2011 (introduced in v7.21);
*) switch - fixed rare possibility of tx-timeout or simultaneous flap of all switch ports on devices with Alpine CPUs;
*) switch - increase "ingress-rate" and "egress-rate" maximum value to 400G;
*) timezone - updated timezone information from "tzdata2026b" release;
*) upgrade - prevent package scheduling from interfering with the upgrade feature;
*) vxlan - fixed fast-path when using "checksum=no" (introduced in v7.20);
*) winbox - do not pre-fill "Allowed Address" and "Client Allowed Address" with "::/0" when adding new WireGuard Peer;
!) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;
*) app - fixed "reset" not working with certain apps;
*) app - fixed home-assistant default config files;
*) app - only generate secrets for enabled apps;
*) app - resolved issue where duplicate swaps are created;
*) bfd - fixed delay on session print;
*) bgp - added option to add BGP VPLS created interfaces in interface-list;
*) bgp - fixed advertisement print handling by "dst" when destination is in VRF;
*) bgp - fixed IPv6 End-of-Route processing;
*) bgp - improved stability on MP (multiprotocol) parsing;
*) certificate - always use all trust stores for downloaded CRL validation;
*) container - fixed missing config.json issue when upgrading from version 7.20.8 or older;
*) interface - fixed duplicate MAC warning for wireless, wifi, macsec, w60g interfaces (introduced in v7.23);
*) ipsec - fixed policy move handling;
*) ipsec,ike2 - fixed active connection termination;
*) ipsec,ike2 - fixed SA payload validation;
*) ipsec,ike2 - improved pending child SA cleanup and removal of dangling SAs during Phase 2 deletion;
*) isis - fixed missing "l2.lsp-refresh-interval" parameter;
*) leds - fixed missing wireless LED configuration (introduced in v7.21);
*) lte - fixed cases where EC25-EU and EG25-G boards would receive packets with missing last 4 bytes;
*) ospf - added missing "type=ptmp-broadcast" parameter to "/routing/ospf/interface" menu;
*) ospf - allow comments on static interfaces;
*) ospf - fixed interface passive flag update in WinBox;
*) pim - added comment for "/routing/gmp" entries;
*) ppp - improved system stability;
*) route - fixed static route flag handling by WinBox on disable;
*) routerboard - renamed "ipq53xx" firmware type to "ipq5300";
*) switch - increase "ingress-rate" and "egress-rate" maximum value to 400G;
*) upgrade - prevent package scheduling from interfering with the upgrade feature;
*) winbox - added missing values to "AFI" setting under "Routing/BGP" menus;
*) winbox - do not pre-fill "Allowed Address" and "Client Allowed Address" with "::/0" when adding new WireGuard Peer;
*) winbox - fixed value unset under "MPLS/LDP Neighbor" menu;
*) app - fixed bogus configuration export;
*) app - fixed making empty directories when running configuration export;
*) bgp - fixed memory leak;
*) bridge - fixed stability issue when using DHCPv4 snooping;
*) disk - avoid reading SCSI stats all the time to allow disks to go to sleep;
*) disk - improved error message when a swap file is created without "file-size" specified;
*) ethernet - fixed stability issue with TSO on Alpine CPUs;
*) firewall - improved system stability;
*) ipsec,ike2 - improved TSi validation to prevent modecfg address conflicts;
*) ipv6 - do not disable IPv6 FastPath when Traffic Flow is enabled;
*) ospf - added missing interface parameters;
*) ospf - fixed unresolved route problem when "routing-table" setting is used;
*) ptp - rename "smpte" to "smpte-2059";
*) route - improved overall stability;
*) route - removed deprecated "/routing/route/rule" menu;
*) switch - fixed rare possibility of tx-timeout or simultaneous flap of all switch ports on devices with Alpine CPUs;
*) console - fixed unresponsiveness when entering safe-mode through the Windows 11 terminal;
*) ethernet - fixed stability issue after switch reset on devices with IPQ-40xx, IPQ-60xx CPUs (introduced in v7.22);
*) vrrp - fixed stability issue when using VRRP with a hardware-offloaded bridge for Marvell Prestera switch chip;
*) app - fixed uptime-kuma and jupyter-notebook;
*) bgp - fixed stability issue when non-existent output select-chain was specified;
*) bridge - fixed missing dynamic "switch-cpu" VLAN entry in WiFi setup;
*) bridge - synchronize only local bridge MAC addresses for MLAG (introduced in v7.22);
*) console - rename "cpu-used-per-cpu" to "cpe-used-per-core" in "/system/resource/monitor";
*) container - fixed losing container after reboot;
*) ethernet - fixed false excessive broadcast warning (introduced in v7.20);
*) firewall - improved system stability;
*) ipsec - fixed expired SA handling to prevent “no such item” errors during listing;
*) ipv6,ra - use received prefix when RA on-link flag is 0 (introduced in v7.22);
*) isis - improved stability with fragmented CSNP;
*) leds - fixed default LED configuration for CCR2004-1G-12S+2XS;
*) leds - fixed LED dark mode for RB5009;
*) lte - fixed missing automatic redial when cellular connectivity is lost for R11e-LTE;
*) ospf - improved stability on configuration change;
*) ovpn - fixed OVPN push routes;
*) poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - fixed occasional detection issue when using auto-on mode;
*) ptp - allow manual domain configuration for 802.1AS profile;
*) ptp - set DSCP (EF) for the default profile when using IPv4;
*) route - improved service stability when removing routes;
*) routerboard - fixed applying settings via WinBox on devices with fixed CPU frequency;
*) system - added FCC Part 15 Compliance label to "System/Regulatory" menu;
*) system - improved stability for internal RouterOS service communication;
*) system - improved system stability;
*) system - included full certificate chain to Windows executables;
*) usb - fixed crash when using Ethernet adapter (introduced in v7.22);
*) vrrp - fixed packet drop in CHR (introduced in v7.22);
*) wifi - improved authentication stability for WiFi 7 access points;
*) wifi-mediatek - fixed communication issues on 802.11ax access points with Intel clients;
*) wifi-mediatek - fixed HE capabilities IE on 2GHz band;
*) wifi-qcom-be - fixed forwarding of 4-address data from station to station;
*) winbox - added option to configure built-in trust store for all services;
*) www - improved service stability when cancelling REST API sessions;
*) bgp - fixed stability issue when non-existent output select-chain was specified;
*) bgp-vpn - allow modifying scopes with routing filters;
*) bgp-vpn - fixed non-working import filter after reboot;
*) bgp-vpn - use target scope for imported route;
*) bridge - fixed missing dynamic "switch-cpu" VLAN entry in WiFi setup;
*) bridge - fixed performance regression in complex setups with vlan-filtering (introduced in v7.20);
*) console - removed the "reset" command from shared settings menus (IP/IPv6/Bridge/L3HW/Neighbor-Discovery/Connection-Tracking);
*) container - fixed issue where the container might not start after upgrading if root-dir was not set;
*) container - improved error message if a container fails to start;
*) defconf - fixed L009 configuration (introduced in v7.21);
*) ethernet - fixed false excessive broadcast warning (introduced in v7.20);
*) firewall - improved system stability;
*) ipsec - improved aes256-ctr stability on L009;
*) ipsec - removed modp8192 proposal on MIPS architectures;
*) ipv6,ra - use received prefix when RA on-link flag is 0;
*) isis - improved stability with fragmented CSNP;
*) l2tp - improved system stability on TILE architecture;
*) l3hw - fixed missing VLAN counters after reboot (introduced in v7.21);
*) l3hw - fixed stability issue (introduced in v7.21);
*) leds - fixed default LED configuration for CCR2004-1G-12S+2XS;
*) log - do not provide non-existent logging topics for configuration;
*) lte - fixed framed route support for the first APN;
*) lte - fixed missing automatic redial when cellular connectivity is lost for R11e-LTE;
*) lte - fixed user set MTU not applied to LTE interface;
*) lte - override the "auto" or 0 MTU in "interface" menu to 1500;
*) ospf - fixed typos in log messages;
*) ospf - improved stability on configuration change;
*) ovpn - fixed OVPN push routes;
*) poe-out - firmware update for CRS354-48P-4S+2Q+ (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - fixed rare PoE-Out firmware upgrade failure on CRS354-48P-4S+2Q+;
*) ptp - allow manual domain configuration for 802.1AS profile;
*) ptp - set DSCP (EF) for the default profile when using IPv4;
*) qos-hw - display queue0 limits for CPU port;
*) qos-hw - fixed "offline" tx-manager ability to queue at least one packet (introduced in v7.21);
*) qos-hw - prohibit setting CPU port with "offline" tx-manager;
*) route - added SLAAC route redistribution for IPv6 capable routing protocols;
*) route - do not set blackhole flag for synthetic routes;
*) route - improved service stability when removing routes;
*) routerboard - fixed applying settings via WinBox on devices with fixed CPU frequency;
*) routing-filter - added possibility to match SLAAC and bgp-mpls-vpn route types;
*) ssh - make login process asynchronous;
*) switch - fixed stability issue when changing bridge multicast-router property on CRS1xx/2xx (introduced in v7.19);
*) system - added FCC Part 15 Compliance label to "System/Regulatory" menu;
*) system - improved stability for internal RouterOS service communication;
*) system - improved system stability;
*) system - improved upgrade service stability when the server is unreachable;
*) system - included full certificate chain to Windows executables;
*) user - properly apply login delay (introduced in v7.20);
*) wifi-mediatek - fixed communication issues on 802.11ax access points with Intel clients;
*) wifi-mediatek - fixed HE capabilities IE on 2GHz band;
*) winbox - fixed "Remote AS" setting under the "Routing/BGP/Connections" menu;
*) winbox - fixed "Src/Dst Address Type" under the "IP/Firewall/NAT" menu;
*) winbox - fixed L3HW default value for VLAN interface (introduced in v7.21);
*) winbox - properly display multiple bands for multi-link interface clients under registration table;
*) winbox - rearrange filter wizard parameters in tabs;
*) www - improved service stability when cancelling REST API sessions;
*) bgp-vpn - fixed non-working import filter after reboot;
*) certificate - added option to configure built-in trust store for all services (CLI only);
*) certificate - use "default" for built-in trust store default value;
*) chr - improved virtio_net stability;
*) console - removed the "reset" command from shared settings menus (IP/IPv6/Bridge/L3HW/Neighbor-Discovery/Connection-Tracking);
*) defconf - fixed architecture detection for apps;
*) hardware - name serial devices after port names;
*) hardware - name storage hardware devices after slot name in "/disk" menu;
*) l3hw - fixed a system stability issue (introduced in v7.21);
*) leds - allow multiple interface selection for interface-activity trigger;
*) log - do not provide non-existent logging topics for configuration;
*) log - fixed "/system/logging/action/get" command (introduced in v7.22);
*) lte - fixed LTE modem automatic modeswitch (introduced in v7.22);
*) lte - fixed Tx stat reporting in LTE passthrough mode (introduced in v7.22);
*) qos-hw - display queue0 limits for CPU port;
*) qos-hw - fixed "offline" tx-manager ability to queue at least one packet (introduced in v7.21);
*) qos-hw - prohibit setting CPU port with "offline" tx-manager;
*) quickset - fixed configuration of multi-link APs;
*) ssh - make login process asynchronous;
*) switch - disable EEE on RB5009 and CCR2004-16G-2S+ devices;
*) system - fixed total memory reporting on hAP be3 Media;
*) tr069 - fixed modem extended revision reporting;
*) wifi - fixed bridge VLAN configuration for multi-link interfaces;
*) wifi - fixed EAP authentication for multi-link clients;
*) wifi - improved link-specific parameter application after reboot for multi-link interfaces;
*) wifi - improved stability during association;
*) winbox - added "Supported HW Caps" and "Multi Link Mode" configuration options under the "WiFi/Provisioning" menu;
*) winbox - do not set empty chain when adding/editing routing rule;
*) winbox - fixed "Remote AS" setting under the "Routing/BGP/Connections" menu;
*) winbox - fixed "Src/Dst Address Type" under the "IP/Firewall/NAT" menu;
*) winbox - make the band field on the WiFi registration table multi-argument;
!) certificate - added support for multiple ACME certificates (services that use a previously generated certificate need to be reconfigured after the certificate expires);
!) device-mode - added option to configure device-mode via Netinstall or FlashFig using a “mode script”;
*) app - added configurable app-store URL for custom apps;
*) app - added health check for apps, which automatically rewrites the composed YAML;
*) app - added jupyter-notebook, livebook, myip, and rustfs apps;
*) app - added support for custom apps;
*) app - allow configuring bridge port pvid for app;
*) app - changed ui-url parameter for Smokeping and Nextcloud;
*) app - clean the backup directory after container repull;
*) app - do not show duplicate entries of required-mounts;
*) app - enable swap on all devices that use apps to help with performance;
*) app - fixed /app/export;
*) app - fixed apps constantly polling the cloud;
*) app - fixed elasticsearch, element, pmacct-netflow apps failing to start;
*) app - fixed issue with Cinny not being able to create a root-dir;
*) app - fixed missing reverse-proxy URL;
*) app - fixed potential port collisions between apps;
*) app - show app URL only when it is running;
*) app - show DNS URL for app only if it has a reverse-proxy;
*) bgp - added BGP unnumbered support;
*) bgp - changed multipath to number argument;
*) bgp - fixed BGP output sometimes not being cleaned after session restart;
*) bgp - fixed early-cut not working properly;
*) bgp - fixed ignore-as-path-len not being used;
*) bgp - fixed update messages not being sent on default-prepend value change;
*) bgp - implemented add-path;
*) bgp - implemented multipath (ability for BGP best path to select ECMP routes);
*) bgp - make remote.address parameter optional;
*) bgp-vpn - allow modifying scopes with routing filters;
*) bgp-vpn - use target scope for imported route;
*) bridge - added local and static MAC synchronization for MLAG;
*) bridge - added MLAG support per bridge interface (/interface/bridge/mlag menu is moved to /interface/bridge; configuration is automatically updated after upgrade; downgrading to an older version will result in MLAG configuration loss);
*) bridge - added MLAG-specific aged and aged-peer flags to host table;
*) bridge - added RA guard feature;
*) bridge - fixed MAC moving between regular ports and bonds for MLAG;
*) bridge - fixed MLAG state being permanently disabled when changing bridge interface settings;
*) bridge - fixed performance regression in complex setups with vlan-filtering (introduced in v7.20);
*) bridge - improved logic for interface remove;
*) bridge - improved MAC synchronization for MLAG;
*) bridge - improved VRRP MAC address handling;
*) bridge - removed vlan-filtering check when changing the MVRP setting (allows disabling MVRP through WinBox);
*) bth - use separate Let's Encrypt certificate for file-share;
*) certificate - improved certificate export process;
*) certificate - improved logging;
*) chr - improved fast-path stability when using vmxnet3 driver;
*) console - added :continue and :break commands for various loops;
*) console - added :exit command to terminate scripts;
*) console - added "comments" parameter to print command to control comment and error output;
*) console - added comparison operators for ID values;
*) console - added Ctrl+Left/Right word navigation;
*) console - added Ctrl+w word deletion;
*) console - added hint for dry-run import parameter;
*) console - added left shift (<<) and right shift (>>) support for IPv6 addresses;
*) console - added on-event script runner support to print follow/follow-only;
*) console - added timestamp support to print follow/follow-only;
*) console - allow undefined variables in dry-run import;
*) console - changed autocomplete expansion criteria;
*) console - disable follow command in /ip/firewall/connection menu;
*) console - fixed brief print for entries with multiple comments;
*) console - fixed setting of /interface/wireless/scan-list;
*) console - fixed time drift for interface last-link-down-time and last-link-up-time;
*) console - fixed value type names in comparison errors;
*) console - implemented string casting in :tobool command;
*) console - improved command decoding to drop extraneous commands (visible in history logging);
*) console - improved error tracing when using find command;
*) console - improved export command to avoid empty [find];
*) console - improved history logging when performing object rename with set/reset;
*) console - improved set/remove command handling in /file menu;
*) console - look up variable in global scope if argument scope lookup failed;
*) console - parse width parameter for non-interactive SSH commands;
*) console - show smaller QR codes where possible;
*) console - use the same flag output format for both print brief and detail;
*) container - added support for zstd extraction;
*) container - automatically stop/repull/start the container on repull or remote-image change;
*) container - fixed issue where the container may not start after upgrading if root-dir was not set;
*) container - improved error message if container fails to start;
*) container - internal stability improvements;
*) container - use the user-defined envs and envlist for container shell command;
*) defconf - fixed L009 configuration (introduced in v7.21);
*) detnet - added request-interval setting;
*) detnet - changed default port from MNDP to a random unused UDP port;
*) dhcp-server - improved failure/error logging for both IPv4 and IPv6;
*) dhcpv4-client - fixed inability to reference disabled DHCP client by interface name;
*) dhcpv4-client - request DOMAINNAME (15) option from the server;
*) dhcpv4-server - improved DHCP option handling;
*) dhcpv4-server - improved logging;
*) dhcpv4-server - send all found lease options in reply to DHCPINFORM;
*) dhcpv6-client - allow unsetting "pool-prefix-length" parameter;
*) dhcpv6-client - improved log messages;
*) dhcpv6-relay - fixed link-layer address inconsistency with the original link-layer address in relay-forward packets;
*) dhcpv6-server - swap input and output RADIUS accounting statistics counters;
*) disk - added support for file-based swap space;
*) disk - added trim command which functions similarly to fstrim;
*) disk - fixed issue where iSCSI did not work with ESXi and XEN hypervisors;
*) disk - fixed issue with disks not mounting after swapping devices;
*) disk - fixed opening a drive in read-only mode if it became locked;
*) disk - improved BTRFS stability on TILE devices;
*) disk - renamed format file-system=trim and trim-secure to format file-system=discard and discard-secure;
*) disk - show if drive is encrypted and locked;
*) email - use default port if not specified;
*) ethernet - increased Rx buffer size for devices with Alpine CPUs (reduces packet rx-drop in certain cases);
*) fetch - added HTTP/2 support on ARM64 and x86/CHR devices;
*) fetch - fixed fetch treating relative paths from redirects as hostnames;
*) fetch - increased default maximum redirect count to 2;
*) fetch - return error code and HTTP headers to :onerror script;
*) fetch - treat HTTP 304 return code as success;
*) gps - fixed GPS port disappearance after reboot for EC25-EU&KNe;
*) health - added CPU temperature monitoring to L009 with ARM64;
*) hotspot - allow WireGuard interface type;
*) hotspot - check validity of base32 for otp-secret;
*) hotspot - do not invalidate static ARP entries;
*) hotspot - fixed www response after login by cookie;
*) hotspot - set sensitive flag on /ip/hotspot/user otp-secret;
*) ike1 - added ChaCha20-Poly1305 ESP encryption support;
*) ike1,ike2 - improved netlink update handling;
*) iot - added Bluetooth extended scanning and 1M/2M PHY support for the RB924i KNOT devices;
*) iot - added Bluetooth extended scanning, advertising, and 1M/2M/CODED PHY support for EC25 KNOT devices;
*) iot - added modbus delay using interframe-gap setting;
*) iot - improved LoRa FSK modulation downlinking;
*) ip - added error messages to reverse-proxy rules;
*) ip - added reverse-proxy;
*) ip-service - properly disable IP/Service on manual disable;
*) ippool6 - allow creating sub-pool by specifying "from-pool";
*) ipsec - added "none" option to IPsec key QKD certificate field;
*) ipsec - added IKEv2 DDoS cookie activation setting;
*) ipsec - added logging for IPsec policy template group;
*) ipsec - added logging of IKEv2 connection SPI and initiator address;
*) ipsec - adjusted minimum generated PSK key length;
*) ipsec - fixed IKEv2 child policy reqid lost on rekey;
*) ipsec - fixed IKEv2 child reqid handling on traffic selector update;
*) ipsec - improved aes256-ctr stability on L009;
*) ipsec - removed modp8192 proposal on MIPS architectures;
*) ipv6 - added dhcp6-pd-preferred to /ipv6/nd/prefix to control P flag in Prefix Info Option RFC 9762;
*) ipv6 - delete SLAAC default route if there are no active SLAAC prefixes present and no new RAs received;
*) ipv6 - do not generate duplicate dynamic link-local addresses on tunnel type interfaces;
*) ipv6 - enable IPv6 fast-path after removing firewall rules;
*) ipv6 - improved system stability when manipulating IPv6 configuration that was added while IPv6 was disabled;
*) isis - improved stability and fixed a small memory leak;
*) l2tp - improved system stability on TILE architecture;
*) l3hw - fixed missing VLAN counters on reboot (introduced in v7.21);
*) l3hw - improved system stability on device shutdown/reboot;
*) l3hw - improved system stability when enabling VLAN offloading under active traffic (introduced in v7.21);
*) log - added comment support to rule entries;
*) log - added option to clear echo logs;
*) log - added option to prepend topics to BSD syslog message;
*) log - added script target for log actions;
*) log - fixed incorrect log message shown after canceling supout.rif creation;
*) log - fixed minor spelling issues;
*) log - fixed missing ID in trace logs after removing logging rule;
*) log - log "Secret must be set to run scripts from SMS" error only if ":cmd" prefix is used in SMS message;
*) log - use uppercase MAC address in firewall logging;
*) lte - added "auto" MTU option for LTE interfaces to use network-advertised MTU on supported devices;
*) lte - added AT command timeout for EC25-EU&KNe;
*) lte - added multi-apn and framed routing support for EC200A-EU modem (requires latest FW version);
*) lte - added roaming barring field to LTE "show-capabilities" menu;
*) lte - added subscriber number to monitor command for MBIM modems;
*) lte - added USB tethering support using iOS devices;
*) lte - clear about field status on firmware upgrade;
*) lte - do not allow modem firmware-upgrade on "inactive" interface;
*) lte - do not allow setting unsupported roaming barring settings for R11e-4G;
*) lte - do not flap LTE passthrough assigned interface on modem link state change;
*) lte - do not reconfigure LTE interface on configuration change error;
*) lte - enable DHCP relay packet forwarding to the cellular network for EG120K-EA and RG650E-AU;
*) lte - fixed "allow-roaming" setting to return error for modems that do not support roaming barring;
*) lte - fixed cases where AT dialer could get stuck in "modem not ready" state;
*) lte - fixed cases where incorrect network modes and bands could be suggested for active interface;
*) lte - fixed chained firmware update for Chateau 5G;
*) lte - fixed changing eSIM profile nickname;
*) lte - fixed changing MAC address for EC200A-EU modem;
*) lte - fixed crash on LTE passthrough interface deactivation;
*) lte - fixed displaying operator name for Chateau ax R17;
*) lte - fixed eSIM errors appearing on devices without eSIM support;
*) lte - fixed firmware update and status refresh for R11eL-EC200A-EU modem;
*) lte - fixed LTE interface IPv6 address generation to use EUI-64 for EC25-EU&KNe;
*) lte - fixed missing notifications to eSIM provider when eSIM provisioning canceled;
*) lte - fixed tethering support for Google Pixel Pro 8;
*) lte - fixed wrong MTU reading/setting for config-less modems;
*) lte - hide external antenna selection menu for the Chateau AX R17;
*) lte - improved APN IP type handling by enabling only the IP protocols defined in the assigned APN profile for config-less modems;
*) lte - make inactive LTE interface settable, LTE interface settings can be set without waiting for modem initial initialization;
*) lte - removed delay before querying modem status for config-less modems with info channel;
*) lte - show ICCID and IMSI also when the interface is disabled;
*) lte - strip modem reported padding characters for SIM card (ICCID) on Chateau ax R17;
*) mac-telnet - added interface property;
*) macsec - fixed hardware offload on S53 and C53 devices;
*) mesh - fixed missing S flag on interfaces after mesh disable/enable;
*) ospf - fixed typos in log messages;
*) ping - added IPv6 support for flood-ping;
*) poe-out - added LLDP support for dual-signature PDs;
*) poe-out - firmware update for 802.3at capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - firmware update for CRS354-48P-4S+2Q+ (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - fixed controller-error for CRS354-48P-4S+2Q+;
*) port - fixed baud rate change for TILE architecture devices;
*) ppp - added initial support for BG770A-GL modem firmware update;
*) ppp - fixed Framed-Route attribute not being applied to correct VRF;
*) profiler - split "management" process into different smaller process groups;
*) radius - fixed initialization of incoming UDP socket in some situations;
*) radius - fixed RadSec SSL CPU usage increase on closed connections;
*) radius - improved incoming RadSec packet processing on busy service;
*) radius - improved logging;
*) rip,pimsm - separate the interface property from the address in /routing/rip/interface and /routing/pimsm/interface menus;
*) rose-storage - added XFS support;
*) route - added logs for check-gateway state changes;
*) route - added routing/settings policy-rules;
*) route - added SLAAC route redistribution for IPv6 capable routing protocols;
*) route - do not set blackhole flag for synthetic routes;
*) route - fixed route removal after unexpected safe mode termination;
*) route - fixed routes when scope was less than 10;
*) routerboard - allow changing /system/routerboard/settings via Netinstall or FlashFig using a "mode script";
*) routerboot - allow installing ARM64 on L009 device ("/system routerboard upgrade" required; configure "/system/routerboard/settings set preferred-architecture=arm64 boot-device=try-ethernet-once-then-nand"; start Netinstall with ARM64 image and reboot the device (DO NOT load the backup routerboot with reset button); downgrading to older versions must be avoided);
*) routerboot - fixed linking to 1000M-half for KNOT Embedded LTE4 ("/system routerboard upgrade" required);
*) routerboot - fixed possible Netinstall failure for KNOT Embedded LTE4 ("/system routerboard upgrade" required);
*) routing-filter - added possibility to match SLAAC and bgp-mpls-vpn route types;
*) sfp - improved initialization and linking for some QSFP modules;
*) smips - reduced package size and removed ip-scan, mac-scan, ping-speed, flood-ping features;
*) snmp - added 5G NSA connection signal indications: nr-rsrp, nr-rsrq, nr-sinr;
*) snmp - fixed CA band indication;
*) snmp - fixed issue where bulk walk might skip the first OID;
*) snmp - fixed minor memory leak when changing SNMP authentication/encryption passwords;
*) snmp - fixed reply for empty snmpbulkwalk requests;
*) snmp - report maximum "ifSpeed" value if out of bounds;
*) snmp - report RouterOS version in SNMPv2-MIB::sysDescr;
*) ssh - improved logging;
*) supout - wait up to 5 minutes for export to complete and show incomplete output in case of timeout;
*) switch - fixed missing switch-cpu port counters;
*) switch - improved system stability when changing bridge multicast-router property on CRS1xx/2xx (introduced in v7.19);
*) switch - updated switch-marvell.npk driver;
*) system - added reset-configuration keep-apps=yes;
*) system - display serial ports in the /system/resource/hardware menu;
*) system - improved upgrade service stability when the server is unreachable;
*) undo - show user when configuring DHCP server or hotspot with setup command;
*) upgrade - added "password" parameter to "local-upgrade" feature when configuring through CLI;
*) upgrade - added IPv6 support for local package source and mirror;
*) upgrade - fixed local package mirror check interval;
*) upgrade - removed redundant commands from local package menu;
*) usb - updated device ids for ax88179_178a driver;
*) user - properly apply login delay (introduced in v7.20);
*) user-manager - added support for NAS-Identifier attribute;
*) user-manager - always respond to accounting requests;
*) user-manager - do not send Disconnect-Message for unknown usernames for Accounting-Request;
*) user-manager - do not send invalid NAS-Port-Type on CoA/PoD messages;
*) user-manager - fixed unauthenticated access to /PRIVATE/ userman web files;
*) user-manager - show empty value for session NAS-IP-Address if empty;
*) webfig - added missing icons for Firewall table;
*) webfig - added new section "Common names" in skin designer;
*) webfig - added support for collapsible tree view for menus like Interfaces, Files, Queues;
*) webfig - added support for URL fields;
*) webfig - fixed ability to set interworking.realms-raw WiFi interface attribute;
*) webfig - fixed skin designer mobile view for QuickSet and Terminal;
*) webfig - fixed Torch Filters default values;
*) webfig - improved address type field input value validation;
*) wifi - added keepalive message in CAPsMAN data channel;
*) wifi - added optional show-frame=radiotap parameter value to make sniffer display the radiotap header of captured frames;
*) wifi - allow specifying hostname to caps-man-addresses;
*) wifi - fixed channel switching for MediaTek access points;
*) wifi - fixed FT support with wpa2-psk-sha2;
*) wifi - fixed functionality of the wireless-signal-strength LED trigger;
*) wifi - fixed possible certificate failure after CAPsMAN disable/enable;
*) wifi - improved spectral-history width for console;
*) wifi - improved stability and fixed multiple issues;
*) wifi - improved stability of interfaces in station mode during roaming;
*) wifi - improved support for 802.11be access points;
*) wifi - improved system stability when using spectral-scan;
*) wifi - introduced /interface/wifi/network menu for higher level network configuration (CLI only);
*) wifi - quicker re-connections to APs for interfaces in station mode;
*) wifi - updated regulatory information for Malaysia;
*) wifi-mediatek - fixed rx chains functionality;
*) wifi-mediatek - updated driver and firmware;
*) winbox - added "Force Check" for local upgrade;
*) winbox - added comment in "System/Ports/Remote Access" menu;
*) winbox - added confirmation message to Format Drive;
*) winbox - added Container Repull command;
*) winbox - added error reporting to CAPsMAN Manager menu;
*) winbox - added GUI support for IPsec QDK;
*) winbox - added missing LoRa channel fields;
*) winbox - added missing route flags;
*) winbox - added route ISIS tab;
*) winbox - added socsify icon for firewall NAT rules;
*) winbox - added SwOS Allow From field;
*) winbox - added warning when changing global script variables;
*) winbox - allow using specified skin without the sensitive policy;
*) winbox - fixed applying a skin to a user authenticated with RADIUS;
*) winbox - fixed applying a skin to WinBox if it was uploaded via the branding package;
*) winbox - fixed default flag in certain menus;
*) winbox - fixed empty "Realm Raw" value processing and value inheritance from configuration template (requires WinBox 4);
*) winbox - fixed L3HW default value for VLAN interface (introduced in v7.21);
*) winbox - fixed modem firmware-upgrade for the RG650E-EU modem;
*) winbox - fixed the "New QoS Profile" field for switch rules;
*) winbox - make File Share URL field clickable;
*) winbox - move "Default" panel from "IPv6/ND/Proxy" to "IPv6/ND/Prefixes";
*) winbox - rearrange filter wizard parameters in tabs;
*) winbox - recognize imported certificate key size;
*) winbox - rename "Change Now" to "Change" button in "System/Password" menu;
*) winbox - replace "DHCP" with "DHCPv6" in IPv6 menus;
*) winbox - set "Mount Filesystem" by default under "System/Disk" menu;
*) winbox - show MPLS tab only to relevant routes;
*) winbox - show separator after "Protocol" field for IPv6 Firewall rules;
*) winbox - show warnings in "MPLS/Traffic Eng/Tunnel" menu;
*) winbox - updated some setting and title names;
*) winbox - updated various WiFi properties;
*) wireguard - fixed private key generation when creating a WireGuard interface;
*) wireguard - improved stability;
*) wireguard - merged upstream fixes and improvements;
*) wireless - avoid joining BSS that previously failed until all other options tried;
*) wireless - improved system stability when changing nstreme mode;
*) wireless - improved system stability when eap-method=passthrough configured for station;
*) x86 - added JME network driver;
*) x86 - fixed interface hang on RTL8125 when processing IP-fragmented UDP traffic;
*) x86 - improved link establishing on Intel X710 series NIC;
*) bgp - fixed route refresh subcode 0 warning;
*) bgp - implement revised input error handling per RFC 7606;
*) bridge - fixed dynamic switch-cpu VLAN creation (introduced in v7.20.7);
*) container - fixed nftables/iptables not working with "Message too long" error;
*) health - fixed fan and PSU state logging for MIPSBE devices;
*) poe-out - firmware update for 802.3bt capable boards (the update will cause a brief power interruption to poe-out interfaces);
*) poe-out - fixed PSU state recovery upon unplug/replug on CRS320;
*) ppp - added initial support for BG770A-GL modem firmware update;
*) route - prevent creating routing tables with the same name;
*) routing-filter - fixed num-set matcher;
*) sfp - fixed sfp-ignore-rx-loss parameter for RB760iGS;
*) snmp - fixed handling of the script "dont-require-permissions" parameter when executing scripts using MIKROTIK-MIB::mtxrScriptRunOutput;
*) snmp - fixed permission error reporting when executing scripts using MIKROTIK-MIB::mtxrScriptRunOutput (introduced in v7.20.7);
*) snmp - fixed script "run-count" update after execution;
*) system - fixed rare partial loss of RouterOS configuration;
*) user-manager - properly release database backup file after backup creation;
*) w60g - fixed possible memory leak when an interface is disabled;
*) zerotier - improved route removal;