Impact
RouterOS WebFig exposes an unauthenticated file‑read flaw in the /jsproxy endpoint. A stale, uninitialized principal pointer is retained in a new session, allowing the file‑serving code to dereference it with elevated rights. An attacker may craft a request whose encrypted URI contains parent‑directory components, thereby escaping the WebFig namespace and reading any root‑owned file, such as configuration stores that contain credentials. This flaw can be exploited without authentication and can leak sensitive data from the system.
Affected Systems
The flaw affects Mikrotik RouterOS deployments. Any device running RouterOS versions before 6.49.21 in the long‑term branch, before 7.23.4 in the long‑term branch, or before 7.24.2 in the stable branch is vulnerable. All affected releases use the WebFig interface exposed on the router, and the vulnerability can target all builds from those points.
Risk and Exploitability
The CVSS base score of 8.7 places this vulnerability in the high‑severity range. EPSS data is not available, and the flaw is not yet listed in the CISA KEV catalog, yet CERT reports that the vulnerability is actively exploited. The attack vector likely involves sending a specially crafted /jsproxy request over HTTP/HTTPS to the router’s WebFig service. Because the flaw is unauthenticated, an adversary on the network that can reach WebFig can read arbitrary files, potentially compromising credentials and configuration. The lack of authentication makes the risk significant, especially for routers exposed to untrusted networks.
OpenCVE Enrichment