[1] https://www.microsoft.com/security/blog/2022/03/16/uncoverin...
Default creds (configuration issue) Common creds via bruteforce (configuration issue) Exploit of CVE-2018-14847 (4 year old patched vulnerability).
All of the methods mentioned require local network access in a default configuration. None of these are issues from the public internet.
If you have lateral movement within most networks, you're already likely to have the ability to route and disguise traffic and use the network as a relay point.
I am interested to read of your "many other examples". I'm yet to see a serious network gear vendor without big vulnerabilities to their name. From memory, Cisco had about 4 backdoor root accounts found and CVE'd in 2018 alone.
open the management ports up to the internet (not the default) and be running a firmware prior to April 2018 (or be using a default password)
I've got some of their switches running SwitchOS, which is great, but my minute exposure to winbox has thoroughly put me off anything that uses RouterOS.
(1) SSH into you box for shell and use the command line interface (2) Use the comprehensive web interface (3) use the shell tool in the web interface (4) use wine to run the client