important · Edge — Routers
An unauthenticated WebFig caller can read root-owned RouterOS configuration files and credentials.
Affects
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
A caller needs only network access to /jsproxy. A stale principal pointer supplies file authority, while encrypted parent-directory components escape WebFig's intended namespace.
Detail and 3 sources
The resulting read reaches root-owned configuration stores containing credentials.
MikroTik published a fix, but pre-fix RouterOS images remain accepted.