This was patched months ago. Just another exploit for an old vuln. On Oct 7, 2018, 10:05 -0400, John Ricketts john@quintex.com, wrote:
Fresh from DerbyCon/Jacob Barnes:
"Hey @derbycon if you didn't wake up early enough to catch my talk, I just dropped a variation on CVE-2018-14847 that allows attackers to remotely root a Mikrotik router: "
https://github.com/tenable/routeros/tree/master/poc/bytheway