Skip to content
Topic

Data theft

Reading files, memory, or credentials that should not be accessible: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per CVE-2025-56566
Security Medium · 4.6
CVE-2025-56566

Cleartext credentials on SPI flash

MikroTik firmware 7.19.4 stores authentication credentials and network state in cleartext on non-volatile memory. An attacker with physical access to the device can extract this data from an SPI flash dump without authenticating. No corrective versions or specific mitigations have been communicated by the vendor.

2 min read
Illustrazione per CVE-2026-56719Security
CVE-2026-56719

Out-of-bounds Read in the SMB Daemon of RouterOS

CVE-2026-56719 is an Out-of-bounds Read vulnerability in the SMB daemon of MikroTik RouterOS. It affects versions up to 7.11.2 and 6.49.18, allowing an unauthenticated attacker to read sensitive memory via a manipulated SMB1 frame. Updating to version 7.24.0 resolves the issue; alternatively, disabling the SMB service eliminates the exposure.

Medium · 6.5
Illustrazione per CVE-2026-67281Security
CVE-2026-67281

Unauthorized file read in WebFig

CVE-2026-67281 is an unauthenticated file read vulnerability in the WebFig service of RouterOS that allows an attacker to access restricted files, including credential databases. It affects 7.x versions lower than 7.23.4 and 7.24.2. You must update the firmware or disable remote access to WebFig.

High · 7.5
Illustrazione per CVE-2023-41570Security
CVE-2023-41570

Unauthorized access to the REST API in RouterOS

CVE-2023-41570 is an access control vulnerability in the RouterOS REST API that allows an authenticated user with low privileges to access sensitive data. It affects versions 7.1 through 7.11. Updating to version 7.12 or later resolves the issue; alternatively, you must restrict access to the REST API to trusted hosts only.

Medium · 5.3
Illustrazione per CVE-2026-7668Security
CVE-2026-7668

Out-of-bounds read in SCEP Endpoint

CVE-2026-7668 is an out-of-bounds read vulnerability in the SCEP Endpoint component of RouterOS 6.49.8, exploitable remotely without authentication. It affects only version 6.49.8; the vendor recommends upgrading to the latest available v6.x or 7.x version. It is not known to be actively exploited and is not included in the CISA KEV catalog.

High · 7.3
Illustrazione per CVE-2019-3943Security
CVE-2019-3943

Directory traversal in RouterOS via Winbox and HTTP

CVE-2019-3943 is a directory traversal vulnerability that allows an authenticated user to read and write files outside the /rw/disk sandbox directory via the HTTP or Winbox interfaces. It affects Stable versions 6.43.12 and earlier, Long-term versions 6.42.12 and earlier, and Testing versions 6.44beta75 and earlier. You must update to a version later than those indicated or restrict access to the affected interfaces from untrusted networks.

High · 8.1
Illustrazione per CVE-2018-14847Security
CVE-2018-14847

WinBox Vulnerability in RouterOS

CVE-2018-14847 is a critical vulnerability in the WinBox component of MikroTik RouterOS that allows an unauthenticated attacker to read arbitrary files and an authenticated attacker to write new ones. The vulnerability is present in RouterOS versions up to and including 6.42 and is listed in the CISA KEV catalog, indicating active exploitation. You must update the firmware to a version later than 6.42 and restrict access to the WinBox service to the management network.

Critical · 9.1Exploited