Skip to finding
important · Edge — Routers

An unauthenticated WebFig caller can read root-owned RouterOS configuration files and credentials.

Affects

MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.

A caller needs only network access to /jsproxy. A stale principal pointer supplies file authority, while encrypted parent-directory components escape WebFig's intended namespace.

Detail and 3 sources

The resulting read reaches root-owned configuration stores containing credentials.

MikroTik published a fix, but pre-fix RouterOS images remain accepted.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 6, 2026