AI description
CVE-2026-67281 describes an unauthenticated file-read vulnerability found in MikroTik RouterOS WebFig. This flaw exists within the `/jsproxy` path, where a newly allocated session can retain a stale, uninitialized principal pointer used for file authorization. An attacker can exploit this by manipulating the allocator to dereference the pointer with sufficient rights, then using parent-directory components in an encrypted URI to escape the WebFig file namespace. This allows for the disclosure of root-owned files, including configuration stores that may contain sensitive credentials. The vulnerability affects various versions of RouterOS, with fixes released in versions 6.49.21 (Long-term), 7.23.4 (Long-term), and 7.24.2 (Stable).
- Description
- RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue affects only 7.x branch was fixed in versions: 7.23.4 (Long-term) and 7.24.2 (Stable)
- Source
- cvd@cert.pl
- NVD status
- Analyzed
- Products
- routeros
CVSS 4.0
- Type
- Secondary
- Base score
- 8.7
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
CVSS 3.1
- Type
- Primary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity
- HIGH
- cvd@cert.pl
- CWE-22
- Hype score
- Not currently trending
🧨🧨🧨 MIKROTRICK 🧨🧨🧨 Weaponized MikroTik RouterOS exploitation framework. - CVE-2026-67279 - CVE-2026-86060 - CVE-2026-67276 - CVE-2026-67281 - CVE-2026-67277 - CVE-2026-67278 - CVE-2025-61481 - CVE-2025-10948 - CVE-2018-14847 Now available at my beloved ❤️
@YogSoth0
8 Sept 2026
4098 Impressions
15 Retweets
61 Likes
69 Bookmarks
4 Replies
1 Quote
MikroTik RouterOS WebFig has a high-severity unauthenticated file-read flaw (CVE-2026-67281, CVSS 8.7). Review patches if these routers are in use. https://t.co/7iDdaSsXUr… via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability #AI #MachineLearning https://t.co/msphV
@ADKCyber
6 Sept 2026
51 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*",
"matchCriteriaId": "FFFF7B28-6339-4B25-B724-69C5144E70CD",
"versionEndExcluding": "7.23.4",
"versionStartIncluding": "7.20",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A41D6B3C-D321-4C61-B3D5-00F8276CB4AC",
"versionEndExcluding": "7.24.2",
"versionStartIncluding": "7.24",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]