Impact
The vulnerability originates from MikroTik RouterOS firmware 7.19.4 storing sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker who can physically access the device, such as by extracting data from an SPI flash dump, can retrieve administrator credentials and configuration details without authenticating or knowing the password, directly compromising the confidentiality of the device’s management interface and network data.
Affected Systems
The specific affected product is MikroTik RouterOS firmware version 7.19.4. No additional vendor or product information was supplied via CNA, implying that any router running this exact firmware release is vulnerable. The scope is limited to that release and any future releases that do not address the cleartext storage issue.
Risk and Exploitability
Exploitation requires physical access to the device, with no network attack vector described. The CVSS score is 4.6, indicating a moderate baseline severity, but the EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Once physical access is achieved, an attacker can read cleartext credentials, potentially compromising device management and the broader network.
OpenCVE Enrichment