important · Edge — RouterOS
Unauthenticated WebFig callers can read root-owned RouterOS files and recover configuration credentials.
Affects
MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.
The stale authorization pointer and encrypted-URI traversal were already tracked; today’s change establishes their reach into root-owned, credential-bearing configuration files.
Detail and 3 sources
WebFig must be reachable, with WAN exposure determined by firewall configuration; pre-fix images remain accepted, and fixes do not reach end-of-life hardware.