Skip to finding
important · Wi-Fi — RouterOS

Unauthenticated WebFig requests can disclose root-owned RouterOS files and stored credentials.

Affects

MikroTik RouterOS, the operating system used by MikroTik routers and wireless network appliances.

Allocator shaping leaves a stale principal pointer in a new /jsproxy session, after which parent-directory components escape the encrypted-URI file namespace.

Detail and 3 sources

Today's change establishes that the reachable scope includes root-owned files and credential-containing configuration stores; MikroTik has shipped fixed releases.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026