{"id":5459,"date":"2017-03-10T13:48:40","date_gmt":"2017-03-10T19:48:40","guid":{"rendered":"http:\/\/gregsowell.com\/?p=5459"},"modified":"2017-03-10T13:48:40","modified_gmt":"2017-03-10T19:48:40","slug":"mikrotik-routeros-v6-37-5-bugfix-v6-38-5-current-and-v6-39rc49-rc","status":"publish","type":"post","link":"https:\/\/gregsowell.com\/?p=5459","title":{"rendered":"MikroTik RouterOS v6.37.5 [bugfix], v6.38.5 [current] and v6.39rc49 [rc]"},"content":{"rendered":"<p>What&#8217;s new in 6.37.5 (2017-Mar-09 11:54):<\/p>\n<p>!) www &#8211; fixed http server vulnerability; <strong>This is presumably the fix for the <a href=\"https:\/\/wikileaks.org\/ciav7p1\/cms\/files\/UsersGuide.pdf\">CIA Hive Exploit<\/a> in the Mikrotik httpd implementation<\/strong><br \/>\n*) chr &#8211; fixed problem when transmit speed was reduced by interface queues;<br \/>\n*) dhcp &#8211; do not listen on IPv4\/IPv6 client to IPv6 MLD packets;<br \/>\n*) dude &#8211; (changes discussed here: https:\/\/wiki.mikrotik.com\/wiki\/Manual:The_Dude_v6\/dude_v6.xx_changelog);<br \/>\n*) export &#8211; do not show &#8220;read-only&#8221; IRQ entries;<br \/>\n*) filesystem &#8211; implemented procedures to verify and restore internal file structure integrity upon upgrading;<br \/>\n*) firewall &#8211; do not allow to set &#8220;time&#8221; parameter to 0s for &#8220;limit&#8221; option;<br \/>\n*) firewall &#8211; fixed import of exported configuration that had updated &#8220;limit&#8221; setting;<br \/>\n*) graphing &#8211; fixed graphing crash when high amount of traffic is processed;<br \/>\n*) hotspot &#8211; fixed rare kernel crash on multicore systems;<br \/>\n*) hotspot &#8211; fixed redirect to URL where escape characters are used (requires newly generated HTML files);<br \/>\n*) hotspot &#8211; show Host table commentaries also in Active tab and vice versa;<br \/>\n*) interface &#8211; do not treat multiple zeros as single zero on name comparison;<br \/>\n*) irq &#8211; properly detect all IRQ entries;<br \/>\n*) l2tp-client &#8211; fixed IPSec policy generation after reboot;<br \/>\n*) lcd &#8211; show fan2 speed only if it is available;<br \/>\n*) leds &#8211; fixed defaults for RBSXT5HacD2nr2;<br \/>\n*) mmips &#8211; improved general stability;<br \/>\n*) rb3011 &#8211; fixed noise from buzzer after silent boot;<br \/>\n*) switch &#8211; fixed crash when trying to configure second master port on the same chipset (RB3011, RB2011, CCR1009-8G-1S+);<br \/>\n*) userman &#8211; allow access to User Manager users page only through &#8220;\/user&#8221; URL;<br \/>\n*) userman &#8211; show warning when no users are selected for CSV file generation;<br \/>\n*) winbox &#8211; added &#8220;add-relay-info&#8221; and &#8220;relay-info-remote-id&#8221; to DHCP relay;<br \/>\n*) winbox &#8211; added H flag to &#8220;\/ip arp&#8221; ;<br \/>\n*) winbox &#8211; added missing &#8220;use-fan2&#8221; and &#8220;active-fan2&#8221; to &#8220;\/system health&#8221;;<br \/>\n*) winbox &#8211; allow shorten bytes to k,M,G in bridge firewall just like in \u201c\/ip firewall\u201d;<br \/>\n*) winbox &#8211; do not hide &#8220;power-cycle-after&#8221; option;<br \/>\n*) winbox &#8211; do not hide 00:00:00:00:00:00 MAC address in unpublished ARPs;<br \/>\n*) winbox &#8211; fixed matching &#8220;connection-state=untracked&#8221; connections;<br \/>\n*) winbox &#8211; fixed typo in \u201c\/system resources pci\u201d list;<br \/>\n*) winbox &#8211; hide advertise tab in Hotspot user profile configuration if &#8220;transparent-proxy&#8221; is not enabled;<br \/>\n*) winbox &#8211; make &#8220;power-cycle-after&#8221; show correct value;<br \/>\n*) winbox &#8211; make &#8220;power-cycle-interval&#8221; not to depend on &#8220;power-cycle-ping-enabled&#8221; in PoE settings;<br \/>\n*) winbox &#8211; properly show BGP communities in routing filters table filter;<br \/>\n*) wireless &#8211; fixed scan tool stuck in background;<br \/>\n*) wireless &#8211; improved compatibility with Intel 2200BG wireless card;<br \/>\n*) wireless &#8211; update Thailand country frequency settings;<\/p>\n<p>What&#8217;s new in 6.38.5 (2017-Mar-09 11:32):<\/p>\n<p>!) www &#8211; fixed http server vulnerability;<\/p>\n<p>What&#8217;s new in 6.39rc49 (2017-Mar-09 12:33):<\/p>\n<p>!) www &#8211; fixed http server vulnerability;<br \/>\n*) capsman &#8211; improved CAP status querying;<br \/>\n*) defconf &#8211; fixed default configuration generation when wireless package is disabled;<br \/>\n*) ike2 &#8211; check child state before allowing rekey;<br \/>\n*) ike2 &#8211; send EAP identity as user-name RADIUS attribute;<br \/>\n*) lte &#8211; added LTE signal level reading for Cinterion modems;<br \/>\n*) queue &#8211; fixed reboot loop when queues were used (introduced in 6.39rc42);<br \/>\n*) rb3011 &#8211; added partitioning support;<br \/>\n*) tr069-client &#8211; added &#8220;Device.Hosts.Host.{i}.&#8221; support;<strong>Glad to see they are still thinking about this &#8211; I see potential for sure.<\/strong><br \/>\n*) userman &#8211; fixed rare crash when User Manager requested file does not exist on router;<br \/>\n*) wireless &#8211; fixed RBSXT5HacD2nr2 small channel support;<\/p>\n<p>v6.37.5 forum topic discussion:<br \/>\nhttps:\/\/forum.mikrotik.com\/viewtopic.php?f=21&#038;t=119373<\/p>\n<p>v6.38.5 forum topic discussion:<br \/>\nhttps:\/\/forum.mikrotik.com\/viewtopic.php?f=21&#038;t=119302<\/p>\n<p>v6.39rc49 forum topic discussion:<br \/>\nhttps:\/\/forum.mikrotik.com\/viewtopic.php?f=21&#038;t=116357<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What&#8217;s new in 6.37.5 (2017-Mar-09 11:54): !) www &#8211; fixed http server vulnerability; This is presumably the fix for the CIA Hive Exploit in\u2026<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[],"class_list":["post-5459","post","type-post","status-publish","format-standard","hentry","category-mikrotik"],"_links":{"self":[{"href":"https:\/\/gregsowell.com\/index.php?rest_route=\/wp\/v2\/posts\/5459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gregsowell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/gregsowell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/gregsowell.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/gregsowell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=5459"}],"version-history":[{"count":1,"href":"https:\/\/gregsowell.com\/index.php?rest_route=\/wp\/v2\/posts\/5459\/revisions"}],"predecessor-version":[{"id":5460,"href":"https:\/\/gregsowell.com\/index.php?rest_route=\/wp\/v2\/posts\/5459\/revisions\/5460"}],"wp:attachment":[{"href":"https:\/\/gregsowell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=5459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/gregsowell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=5459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/gregsowell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=5459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}