Skip to finding
important · Edge — RouterOS

Unauthenticated WebFig callers can read root-owned RouterOS files and recover configuration credentials.

Affects

MikroTik RouterOS, the embedded operating system used by MikroTik routers and network appliances.

The stale authorization pointer and encrypted-URI traversal were already tracked; today’s change establishes their reach into root-owned, credential-bearing configuration files.

Detail and 3 sources

WebFig must be reachable, with WAN exposure determined by firewall configuration; pre-fix images remain accepted, and fixes do not reach end-of-life hardware.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Monday, September 7, 2026