This was patched months ago. Just another exploit for an old vuln.
On Oct 7, 2018, 10:05 -0400, John Ricketts <john(a)quintex.com>om>, wrote:
> Fresh from DerbyCon/Jacob Barnes:
>
> "Hey @derbycon if you didn't wake up early enough to catch my talk, I just
dropped a variation on CVE-2018-14847 that allows attackers to remotely root a Mikrotik
router: "
>
>
https://github.com/tenable/routeros/tree/master/poc/bytheway
>