Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Start by checking whether RouterOS reports the router as flagged: on supported devices, run /system/device-mode/print. If it shows flagged: yes, MikroTik says to assume compromise and audit all settings before re-enabling affected functions or clearing the flag. A missing flag is not proof that the router is clean.

What to do first if you suspect unauthorized access

Stabilize the network and record what you can

If the router is disrupting service or appears to be sending harmful traffic, disconnect it from the WAN or affected network if doing so will not create additional operational risk. Before changing settings, note the model and RouterOS version, and record relevant logs, users, firewall and NAT rules, schedulers, scripts, and services. This is a practical record of the current state, not a guarantee of forensic evidence integrity. For a business network or a suspected intrusion affecting other systems, involve the network or security administrator.

Check RouterOS device mode

In the RouterOS terminal, run /system/device-mode/print. MikroTik says RouterOS can analyze configuration at startup, disable suspicious configuration, and set flagged: yes. Its Device-mode documentation says: “If your system has been flagged, assume that your system has been compromised and do a full audit of all settings before re-enabling the system for use.” MikroTik RouterOS Device-mode documentation

Device-mode is factory-preinstalled on devices running RouterOS v7.17 or later, according to MikroTik. Older versions or unsupported devices may not expose the same signal, so an absent flag does not establish that the device is uncompromised. Do not clear a flag before completing the audit; resetting it requires physical button confirmation or a hard reboot, depending on the documented process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Mikrotik hEX RB750Gr3 5-port Ethernet Gigabit Router
  • hEX also known as RB750Gr3 is a five port Gigabit Ethernet router for locations where wireless connectivity is not required
  • The device has a full size USB port. This new updated revision of the hEX brings several improvements in performance
  • It is affordable, small and easy to use, but at the same time comes with a very powerful dual core 880MHz CPU and 256MB RAM
  • IPsec hardware encryption (~470 Mbps) and The Dude server package is supported, microSD slot on it provides improved r/w speed for file storage and Dude
  • Dimensions: 113x89x28mm; Storage size: 16 MB; Passive PoE (PoE in); PCB temperature monitor, Voltage monitor and Mode button

Audit the router before restoring normal access

Review the router methodically and compare its configuration with a known-good version if you have one. An unfamiliar entry is a reason to investigate, not by itself proof of malicious activity.

  • Accounts and credentials: Check all system users and permissions for accounts you do not recognize. Plan to replace passwords with strong, unique credentials.
  • Management access: Review which interfaces and networks can reach management services, and whether any remote access is expected. Restrict management to trusted networks.
  • Firewall and NAT: Look for unfamiliar rules or changes that expose management services or forward traffic to unexpected destinations. MikroTik recommends preserving the preconfigured firewall rules that block WAN-side access unless there is a secure reason to change them.
  • Services and remote connections: Check enabled management services, proxy or SOCKS settings, VPNs, and tunnels. Disable services and access methods the deployment does not need. MikroTik recommends using a VPN, such as WireGuard, when remote access is required.
  • Automation and name resolution: Inspect scheduled tasks and scripts, along with DNS settings and behavior, for changes you cannot explain.

MikroTik’s security guidance recommends keeping RouterOS current, using a strong non-repeating password, restricting management access, and disabling unnecessary services. MikroTik RouterOS security guidance

Resetting configuration and reinstalling RouterOS are different

A configuration reset removes custom configuration and returns the router to defaults; Netinstall is a separate method for reinstalling RouterOS. Neither choice should be treated as proof that an intrusion is resolved. Pick a recovery path based on what you found, the device model, and whether you need to preserve evidence or maintain service.

Recovery option What it does Important considerations
Reset configuration Runs /system reset-configuration to clear configuration and return the device to defaults. Can interrupt service and remove routing, wireless, VPN, and firewall settings. RouterOS normally saves a backup before reset unless options change that behavior. Button operation varies by model; follow the model’s manual. MikroTik configuration reset guide
Netinstall Reinstalls RouterOS and can be configured to apply an empty configuration. Requires a computer with a suitable network interface and access to the device’s Etherboot procedure. Verify the model, architecture, and correct RouterOS package first. MikroTik Netinstall guide

Be careful with backups and exports

Do not automatically restore an old backup as a shortcut. A binary backup clones configuration and contains sensitive information; MikroTik recommends restoring it on the same RouterOS version. A text export can be reviewed, but it omits system user passwords, SSH keys, installed certificates, and some service databases. Treat either file as sensitive and establish that its contents are trustworthy before using it. MikroTik Backup documentation and Configuration Management documentation

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If preserving evidence or service continuity matters, get qualified network support before resetting or reinstalling. For Netinstall, consult the current MikroTik instructions and the device manual; reset-button timing and functions differ among models.

Secure the router and verify its configuration

  1. After auditing and recovery, change RouterOS system passwords to strong, unique credentials.
  2. Upgrade to the latest RouterOS release supported by the device, checking MikroTik’s current release and security information.
  3. Limit management access to trusted networks, and disable services and interfaces the deployment does not use.
  4. Check users, firewall and NAT rules, DNS settings, and scheduled tasks against the configuration you intend to run.
  5. Where device-mode is available, check its status again. Treat a clean status as one check, not as a guarantee that compromise has been eradicated or that other systems were unaffected.

MikroTik’s security and recovery guidance can change with software releases. Its security page was last updated 2025-01-06; its Device-mode guidance was updated 2026-03-16. Security guidance · Device-mode guidance

Rank #4
Sale
MikroTik MikroTik hAP ax2 US Version (C52iG-5HaxD2HaxD-TC-US)
  • MikroTik RouterBOARD C52iG-5HaxD2HaxD-TC-US (US Version) hAP ax (WiFi6) Quad-Core IPQ-6010 864 MHz, RAM 1GB, RouterOS, License level 4 It's time to supercharge your home network with the Generation
  • hAP ax has everything you might need in a primary home access point - and more
  • Forget endless reviews and comparisons - this is the perfect device for 99% of homes
  • Wireless signal is now stronger than ever
  • Here are the two main ingredients of hAP ax's success: a state-of-the-art dual-band, dual-chain 4-4
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the available signs can and cannot establish

The RouterOS flagged state is a strong reason to treat the device as compromised and conduct a full audit, but the documentation cannot diagnose a particular router without its logs and configuration. Conversely, a missing flag does not rule out unauthorized access, especially on older or unsupported devices. Unfamiliar settings, symptoms, or disruptions need investigation in the context of the router’s intended configuration; none alone establishes what happened or whether another system was affected.

Quick Recap

SaleBestseller No. 4
MikroTik MikroTik hAP ax2 US Version (C52iG-5HaxD2HaxD-TC-US)
MikroTik MikroTik hAP ax2 US Version (C52iG-5HaxD2HaxD-TC-US)
hAP ax has everything you might need in a primary home access point - and more; Forget endless reviews and comparisons - this is the perfect device for 99% of homes
$90.75
Bestseller No. 5
MikroTik L009UiGS-RM
MikroTik L009UiGS-RM
W128339515
$106.91
Best Value

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.