Fleet Vulnerability Scanner
•
RouterOS Automated Audit
MikroTik Security & Weak Password Auditor
Audit edge routers against default credentials, plaintext API ports (8728), legacy services (Telnet/FTP), and firmware CVEs.
Fleet Security Rating
40/100
Immediate remediation required
Vulnerable Nodes
4
Routers failing one or more security checks
Critical Exploits Risk
4
Default credentials or open Telnet/FTP
Monitored Fleet
4
Edge gateways under continuous scan
Westlands-Core-CCR2004
critical
IP: 10.200.0.1 • Port: 8728 • Model: CCR2004-16G-2S+ • Firmware: RouterOS v7.14.3
Security Score
40%
Credentials Strength
Strong
User: api_admin
API Protocol
Plaintext (8728)
Type: API
RouterOS Branch
Patched
RouterOS v7.14.3
Legacy Ports
Blocked
Telnet / FTP / DNS Resolver
Security Finding(s) Requiring Attention
• Default / Weak Admin Credentials:
Router is using administrative username 'api_admin' or a default password vulnerable to dictionary attacks.
Fix: Rotate credentials to a dedicated API service account with high-entropy passphrase.
• Plaintext RouterOS API (Port 8728):
Plaintext API port 8728 is active without TLS encryption. Router credentials can be intercepted on transit.
Fix: Switch to TLS-encrypted API-SSL port 8729 with trusted certificate.
Rongai-Tower-RB5009
critical
IP: 10.200.10.1 • Port: 8728 • Model: RB5009UG+S+IN • Firmware: RouterOS v7.14.1
Security Score
40%
Credentials Strength
Strong
User: api_admin
API Protocol
Plaintext (8728)
Type: API
RouterOS Branch
Patched
RouterOS v7.14.1
Legacy Ports
Blocked
Telnet / FTP / DNS Resolver
Security Finding(s) Requiring Attention
• Default / Weak Admin Credentials:
Router is using administrative username 'api_admin' or a default password vulnerable to dictionary attacks.
Fix: Rotate credentials to a dedicated API service account with high-entropy passphrase.
• Plaintext RouterOS API (Port 8728):
Plaintext API port 8728 is active without TLS encryption. Router credentials can be intercepted on transit.
Fix: Switch to TLS-encrypted API-SSL port 8729 with trusted certificate.
Kasarani-Sportsview-RB4011
critical
IP: 10.200.20.1 • Port: 8728 • Model: RB4011iGS+RM • Firmware: RouterOS v7.13.5
Security Score
40%
Credentials Strength
Strong
User: api_admin
API Protocol
Plaintext (8728)
Type: API
RouterOS Branch
Patched
RouterOS v7.13.5
Legacy Ports
Blocked
Telnet / FTP / DNS Resolver
Security Finding(s) Requiring Attention
• Default / Weak Admin Credentials:
Router is using administrative username 'api_admin' or a default password vulnerable to dictionary attacks.
Fix: Rotate credentials to a dedicated API service account with high-entropy passphrase.
• Plaintext RouterOS API (Port 8728):
Plaintext API port 8728 is active without TLS encryption. Router credentials can be intercepted on transit.
Fix: Switch to TLS-encrypted API-SSL port 8729 with trusted certificate.
Kilimani-Yaya-RB3011
critical
IP: 10.200.30.1 • Port: 8728 • Model: RB3011UiAS-RM • Firmware: RouterOS v7.14.2
Security Score
40%
Credentials Strength
Strong
User: api_admin
API Protocol
Plaintext (8728)
Type: API
RouterOS Branch
Patched
RouterOS v7.14.2
Legacy Ports
Blocked
Telnet / FTP / DNS Resolver
Security Finding(s) Requiring Attention
• Default / Weak Admin Credentials:
Router is using administrative username 'api_admin' or a default password vulnerable to dictionary attacks.
Fix: Rotate credentials to a dedicated API service account with high-entropy passphrase.
• Plaintext RouterOS API (Port 8728):
Plaintext API port 8728 is active without TLS encryption. Router credentials can be intercepted on transit.
Fix: Switch to TLS-encrypted API-SSL port 8729 with trusted certificate.