CVE CVE-2025-56566
Severity MEDIUM · CVSS 3.1 4.6
Weakness CWE-312
Affected versions not yet announced
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-09-16

What is the CVE-2025-56566 vulnerability?

The vulnerability consists of the cleartext storage of sensitive information, such as authentication credentials and network state, within the device’s non-volatile memory. An attacker with physical access can extract this data from an SPI flash dump without authenticating to the device and without knowing the administrator password.

Which RouterOS versions are vulnerable?

The affected versions and fixed versions have not yet been announced. Firmware 7.19.4 is specifically mentioned in the vulnerability description as a version exhibiting this behavior.

Is my router at risk?

A router is exposed if an attacker has physical access to the device. The vulnerability requires access to the non-volatile memory (SPI flash) to extract the cleartext credentials. It is not necessary for the service to be reachable from untrusted networks, as the attack occurs at the hardware level.

Is the CVE-2025-56566 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA.

How to protect the router from CVE-2025-56566?

The primary protection is ensuring the physical security of the device, preventing unauthorized access to the motherboard or flash memory. Since no fixed versions or specific mitigations have been announced by the vendor, it is not possible to apply a software update to resolve the issue.

Which RouterOS commands are needed to mitigate CVE-2025-56566?

Update RouterOS

The only definitive fix is an update. First, save the configuration; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2025-56566?

The CVSS v3.1 score assigned to CVE-2025-56566 is 4.6, with a MEDIUM severity.

Does CVE-2025-56566 require authentication to be exploited?

No, CVE-2025-56566 does not require authentication to the device; the attacker extracts the data directly from the flash memory via physical access.

What is the underlying weakness (CWE) associated with CVE-2025-56566?

The underlying weakness associated with CVE-2025-56566 is CWE-312, defined as “Cleartext Storage of Sensitive Information”.

Is there a RouterOS version that fixes CVE-2025-56566?

The fixed version for CVE-2025-56566 has not yet been announced.

Official sources