Description
MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password.
Published: 2026-09-16
Score: 4.6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cleartext storage of credentials leading to data exposure
Action: Immediate Firmware Update
AI Analysis

Impact

The vulnerability originates from MikroTik RouterOS firmware 7.19.4 storing sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker who can physically access the device, such as by extracting data from an SPI flash dump, can retrieve administrator credentials and configuration details without authenticating or knowing the password, directly compromising the confidentiality of the device’s management interface and network data.

Affected Systems

The specific affected product is MikroTik RouterOS firmware version 7.19.4. No additional vendor or product information was supplied via CNA, implying that any router running this exact firmware release is vulnerable. The scope is limited to that release and any future releases that do not address the cleartext storage issue.

Risk and Exploitability

Exploitation requires physical access to the device, with no network attack vector described. The CVSS score is 4.6, indicating a moderate baseline severity, but the EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Once physical access is achieved, an attacker can read cleartext credentials, potentially compromising device management and the broader network.

Generated by OpenCVE AI on September 22, 2026 at 20:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a MikroTik RouterOS firmware version that no longer stores credentials in cleartext, such as the latest available release.
  • Secure the physical location of routers by restricting access to trusted personnel and implementing tamper‑evidence measures.
  • Restrict or monitor SPI flash read access and detect any unauthorized memory dumps.

Generated by OpenCVE AI on September 22, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Title Cleartext Credential Disclosure via Physical SPI Flash Read in MikroTik RouterOS 7.19.4

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Title Cleartext Storage of Authentication Credentials in MikroTik RouterOS 7.19.4
Weaknesses CWE-200

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Title Cleartext Storage of Authentication Credentials in MikroTik RouterOS 7.19.4
Weaknesses CWE-200
CWE-312

Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Mikrotik
Mikrotik routeros
Vendors & Products Mikrotik
Mikrotik routeros

Wed, 16 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password.
References

Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T16:08:07.927Z

Reserved: 2025-08-17T00:00:00.000Z

Link: CVE-2025-56566

cve-icon Vulnrichment

Updated: 2026-09-22T16:04:00.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T21:17:06.767

Modified: 2026-09-22T19:56:19.073

Link: CVE-2025-56566

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T20:30:08Z

Weaknesses
  • CWE-312

    Cleartext Storage of Sensitive Information