So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.
"Regardless of version used, all RouterOS versions that have the default firewall enabled, are not vulnerable"
I don't believe all MK devices OOTB had the WAN interface firewall'd (they do now though their wAP's run same license level 4 of RouterOS and do not have fw enabled on the ethernet port) though I do recall that being made very clear in both the documentation that came with the hardware and in any wiki/docs I looked at at the time I was first setting up my MK device.
The issue I have is the lack of communication with customers. I have not received any notification of this vuln since August 5th (well since patched in April) but they in general seem rather blase about the whole thing. I haven't followed the link to story but I follow BPR on Twitter and saw that it's around 421K according to censysio.