As to their update availability - I'm fairly certain I could take something they manufactured 15 years ago and update it to the current version, as it all uses the same OS, and they still support every architecture they've used.
The main problem with Mikrotik is that the configuration interface is too low-level and it's easy to fall into such traps.
But as the first comment says - introducing breaking changes is not acceptable and they should appear only in major releases. And then those security bugfixes should be backported on all major versions which were released at least 5 years back. Yesterday I upgraded mikrotik from 6.14 to 6.42 and it took me 30minutes of additional configuration to make everything working again.
Also mikrotik collets a lot of network stats so implementing an algorithm which would restart the router when there's usually the least amount of traffic should be feasible - those updates take less than a minute so it's not like windows 10.
For the firewall I've got pfSense (FreeBSD based firewall) running on an small Intel box from Aliexpress with 6x ethernet ports. I overspecced the machine so I knew it would last for years, whilst allowing running intrusion detection (snort), reverse proxy, auto blacklisting and much more.
This is also acting as my router, but if & when my home network expands I'll add a dedicated one (and probably put 4x ethernet ports bonded using lagg into it as it'll still be controlling my vlans).
I got a dedicated ceiling mount wireless AP from TP-Link.
This has only slightly higher power and space requirements than what I had, but that buys me so much flexibility. I can upgrade and augment individual components when needed (particularly wifi). I have individual vlans, firewalled off from each other, running over three wifi SSIDs - trusted, guest and internet-of-shit. I'm currently connected into my trusted vlan over OpenVPN, so I can connect to my server without having to open any ports to the outside world.
The downsides are that it did take a couple of days to set it all up to my liking, but personally I've learned so much doing it it's been worth every minute.
"Regardless of version used, all RouterOS versions that have the default firewall enabled, are not vulnerable"
I don't believe all MK devices OOTB had the WAN interface firewall'd (they do now though their wAP's run same license level 4 of RouterOS and do not have fw enabled on the ethernet port) though I do recall that being made very clear in both the documentation that came with the hardware and in any wiki/docs I looked at at the time I was first setting up my MK device.
The issue I have is the lack of communication with customers. I have not received any notification of this vuln since August 5th (well since patched in April) but they in general seem rather blase about the whole thing. I haven't followed the link to story but I follow BPR on Twitter and saw that it's around 421K according to censysio.
Edit: I see...*notification via email is what I thought I had written in top post.
They provide regular software updates, and it is imho a good hacker/tinkerer router.
One major advantage of Turris Omnia is that CZ.NIC is a non-profit, so they are not as constrained by profitability of this project, and it's a part of a larger strategy (e.g. you may allow reporting statistics back to turris: https://project.turris.cz/en/global-stats/).
There is this one the horizon though: https://up-shop.org/up-ai-edge/233-up-net-plus.html
It'd make a fine router in the same vein, no word on power usage though.
Their routers were also not affected by the KRACK WPA2 exploit last year.
AVM products cost a lot more than their competitors' but they are really worth their money.
It's 100% worth the extra cash getting an AVM over most ISP routers you get in germany.
They have hardware offloading for routing and iptables, will route 900Mbps, and get regular software updates.
Edgerouter Lite is $99, and draws about 5W.
I would recommend buying something else.
0: https://community.ubnt.com/t5/EdgeRouter/EdgeRouter-X-SFP-le... (reported 2017-03, still alive as of 2018-08)
So MikroTik did its part.