This is for those who are having the HTTP service of mikrotik activated on the internet.
On March 2017 Wikileaks published some documents that supposed to belong to CIA under the name of Vault 7, describing that CIA has an exploit called “ChimayRed” by which can inject malicious code on RouterOS if the HTTP service is not protected.
You can find info and information on solving this, here.