MikroTik

MikroTik CRS317 Password Recovery

Step-by-step password recovery for the MikroTik CRS317 (Cloud Router Switch (RouterOS)). Console access required.

Overview

This guide provides step-by-step instructions for resetting lost or forgotten administrative passwords on enterprise networking hardware. Follow the procedure below carefully to regain access while preserving your device configuration.

Prerequisites

Before proceeding with password recovery, ensure you have a console cable, terminal emulation software configured to 9600 baud, and physical access to the device.

Step 1: Establish Console Connection

Connect your terminal cable to the console port of the device and open your serial terminal session.

Step 2: Interrupt the Boot Sequence

Power cycle the hardware and issue a Break key sequence during initial system startup to enter ROMMON mode.

Step 3: Reset Password & Configuration

Bypass startup configuration loading, boot into system software, set your new credentials, and save changes back to non-volatile memory.

Overview

This procedure recovers administrator access to the MikroTik CRS317 running RouterOS (MikroTik RouterBOARD, Cloud Core Router, Cloud Router Switch, or hEX) when the admin password is lost. RouterOS recovery uses the reset button with two distinct release patterns: a config-preserving password reset (RouterOS v7+) and a full factory reset.

Prerequisites

Physical access to the device's reset button. Optional: console access (RJ-45 serial on CCR/CRS models, micro-USB on some hEX) at 115200 baud, 8N1 to watch boot messages.

Recovery Procedure — Reset Button (RouterOS v6)

  1. Power off the device.
  2. Press and hold the Reset button.
  3. Power on while holding Reset. Keep holding until the ACT (activity) LED starts flashing — this takes about 10–20 seconds (the exact timing varies by model).
  4. Release the button as soon as the ACT LED begins flashing. The device resets to factory defaults (all configuration is cleared).
  5. Log in via console/web as admin with an empty password and reconfigure.

Recovery Procedure — Reset Button (RouterOS v7, config-preserving password reset)

  1. Power off the device.
  2. Press and hold the Reset button.
  3. Power on while holding Reset. Keep holding until the ACT LED flashes once (a single flash after ~10 seconds), then release. This triggers the keep-configuration password reset — the admin password is cleared while the configuration is preserved.
  4. If you keep holding past the first flash until the LED flashes again (or stops flashing), the device performs a full factory reset (config erased).
  5. Log in as admin with an empty password, set a new password: /user set admin password=<new-password>.

Recovery Procedure — Netinstall (last resort, no button access)

  1. Download Netinstall (MikroTik's network boot tool) from mikrotik.com/download.
  2. Connect the device to the PC via the first ethernet port (ether1).
  3. Hold the reset button while powering on, and keep holding until the device enters Netinstall mode (the console shows "Netinstall running" / the ACT LED behaves differently).
  4. Use Netinstall to install a fresh RouterOS — this fully wipes the device and installs a clean system.

Important Notes

Protecting Your Configuration

Regularly export the config: /system backup save name=backup and /export file=backup, and download the files. After recovery, restore with /system backup load name=backup or by pasting the export.