MikroTik shipped that port closed: the flaw is theirs, the exception is yours
On 5 September CERT Polska published six RouterOS vulnerabilities; two of them chained give full control of a MikroTik with no authentication, and Shadowserver counted 122,500 devices with SSH reachable from the internet. The vendor's own advisory says its default configuration blocks that port. So the thing to look at is not the CVE: it is who opened the exception, when, and why nobody gave it an expiry date.