A critical MikroTik RouterOS flaw could let unauthenticated attackers execute code as root or cause denial of service.