Hacker News new | ask | show | jobs
by hyperbovine 1919 days ago
MikroTik hardware is nice but that company has a serious case of nih syndrome. This manifests as a lot of cryptic, undocumented commands plus the occasional showstopper exploit (eg https://nvd.nist.gov/vuln/detail/CVE-2020-13118). As an added benefit, they have a cult of online followers who are all too happy to deride anyone who points these (and other) flaws out as a clueless nontechnical moron. Fwiw I'm transmitting this through one of their routers.
2 comments

That CVE is for third party software. But this brings up a good point. It has a good API surface you can plug into in many ways.

There have been some CVEs, but all the exploits I'm aware of already had patches and were only exploitable for un-updated models.

I honestly don't know what you mean by not invented here. They did create a wireless protocol for point-to-point products with some advantages for those who opt into it, but that's the only thing I can think of.

Sometimes their documentation is lacking, but generally their docs are very good.

Is Mikrotik Router Monitoring System an actual MikroTik software, or is third party open source project? Doesn't seem to be provided by MikroTik: https://github.com/adeoluwa-adebiyi/Mikrotik-Router-Monitori...