That would be fair if this was something people had to enable consciously.
In context, I think it’s pretty victim-blamey to assume people should know 1) the default services running on their router are insecure and 2) that the web config interface is exposed publicly OOTB, instead of only to their LAN.
This is a huge fuckup by Mikrotik, not the users.
E: Checking the docs, I think I was wrong that it’s enabled publicly OOTB. I tried hitting my own router earlier from public IP and it looked like it was getting through, but maybe the traffic was getting bridged automatically.