Description
RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
Published: 2026-09-05
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disclosure of system files, including credential configurations
Action: Immediate Patch
AI Analysis

Impact

RouterOS WebFig contains an unauthenticated file‑read flaw in the /jsproxy endpoint. A newly allocated session retains a stale, uninitialized principal pointer used for file authorization. An attacker can manipulate the memory allocator so that this pointer is dereferenced with sufficient rights and provide parent‑directory components in an encrypted URI to escape the WebFig file namespace, allowing the disclosure of root‑owned files—most notably configuration stores that contain credentials. This weakness corresponds to CWE‑22 (Path Traversal) and CWE‑824 (Stale Pointer).

Affected Systems

The vulnerability affects Mikrotik RouterOS in the 7.x branch. Any 7.x build prior to 7.23.4 in the long‑term release and prior to 7.24.2 in the stable release is vulnerable. Devices running those earlier revisions expose the WebFig interface on the router and are susceptible to the file‑read issue.

Risk and Exploitability

The CVSS score of 8.7 categorizes this as high severity. The EPSS score is below 1%, indicating a low but non‑zero probability of exploitation in the wild, and the flaw is not yet listed in CISA’s KEV catalog. The likely attack vector is an unauthenticated attacker sending a specially crafted /jsproxy request over HTTP or HTTPS to the router’s WebFig service; no authentication is required. If an adversary can reach WebFig from the network, they can read arbitrary high‑privilege files, compromising the router’s confidentiality and configuration integrity.

Generated by OpenCVE AI on September 7, 2026 at 15:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RouterOS to 7.23.4 (long‑term) or 7.24.2 (stable) depending on your branch.
  • If the patch is not yet applied, limit WebFig access to trusted networks with firewall rules or access lists.
  • Preferably tunnel management traffic through a secure VPN or restrict WebFig to known IP ranges so only authorized personnel can reach it.

Generated by OpenCVE AI on September 7, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 25 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
References

Mon, 07 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable) RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)

Sat, 05 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue was fixed in versions: 6.49.21 (Lont-term), 7.23.4 (Lont-term) and 7.24.2 (Stable) RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)

Sat, 05 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
Description RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue was fixed in versions: 6.49.21 (Lont-term), 7.23.4 (Lont-term) and 7.24.2 (Stable)
Title Unauthenticated file read in Mikrotik RouterOS
First Time appeared Mikrotik
Mikrotik routeros
Weaknesses CWE-22
CWE-824
CPEs cpe:2.3:a:mikrotik:routeros:*:*:*:*:*:*:*:*
Vendors & Products Mikrotik
Mikrotik routeros
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-09-08T15:32:07.407Z

Reserved: 2026-07-29T11:59:30.538Z

Link: CVE-2026-67281

cve-icon Vulnrichment

Updated: 2026-09-08T15:32:03.306Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-05T20:17:18.547

Modified: 2026-09-25T14:21:17.737

Link: CVE-2026-67281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T15:45:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-824

    Access of Uninitialized Pointer