Skip to content
Topic

WinBox and WebFig

WinBox, WebFig, and the router’s web management service: all dojo articles on this topic.

Image generated locally with ComfyUI from randomly selected elements. How the images are created

Illustrazione per Safe Mode di MikroTik: come funziona la rete di sicurezza di RouterOS
Knowledge base
Knowledge base · Safe Mode

MikroTik Safe Mode: How RouterOS’s Safety Net Works

Safe Mode is RouterOS's safety net: while it is active, the router logs every change and, if the session that made them drops, it rolls them back automatically. You enable it with Ctrl+X (or F4) in the terminal and with the Safe Mode button in WinBox. It holds up to 100 actions and does not cover commands that restart the router.

8 min read
Illustrazione per CVE-2018-14847: Recupero password in chiaro da user.dat su RouterOS v6Lab
Lab · CVE-2018-14847

CVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6

We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.

Illustrazione per RouterOS 6.49.23 long-term: correzione CVE-2026-84411Firmware
RouterOS 6.49.23 · long-term

RouterOS 6.49.23 long-term: CVE-2026-84411 fix

MikroTik has released version 6.49.23 of the long-term channel for RouterOS 6. The update includes a critical security fix (CVE-2026-84411) and system stability improvements. Installation is recommended on all production devices using the conservative branch, after creating a full backup.

Illustrazione per CVE-2026-84411Security
CVE-2026-84411

Critical vulnerability in RouterOS web service

CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.

Critical · 9.8
Illustrazione per CVE-2026-67281Security
CVE-2026-67281

Unauthorized file read in WebFig

CVE-2026-67281 is an unauthenticated file read vulnerability in the WebFig service of RouterOS that allows an attacker to access restricted files, including credential databases. It affects 7.x versions lower than 7.23.4 and 7.24.2. You must update the firmware or disable remote access to WebFig.

High · 7.5
Illustrazione per CVE-2025-61481Security
CVE-2025-61481

WebFig Exposed in Clear on RouterOS and SwOS

CVE-2025-61481 exposes the WebFig management interface of RouterOS v.7.14.2 and SwOS v.2.18 via unencrypted HTTP, allowing a man-in-the-middle attacker to inject JavaScript into the administrator's browser and intercept credentials. The vulnerability is classified as critical with a CVSS score of 10.0. To mitigate the risk, disable WebFig if not necessary or restrict access exclusively to the trusted management network.

Critical · 10.0
Illustrazione per CVE-2024-54772Security
CVE-2024-54772

Account Enumeration in Winbox on RouterOS

CVE-2024-54772 allows an attacker to identify valid usernames on a MikroTik router by analyzing differences in Winbox service response times. Affected versions include long-term 6.43.13 through 6.49.13 and stable 6.43 through 7.17.2. To mitigate the risk, upgrade to version 6.49.18 or later and restrict Winbox access to the management network.

Medium · 5.4
Illustrazione per CVE-2023-30800Security
CVE-2023-30800

Heap corruption in RouterOS 6 WebFig

CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.

High · 7.5
Illustrazione per CVE-2023-30799Security
CVE-2023-30799

Arbitrary code execution on RouterOS

CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.

High · 7.2
Illustrazione per CVE-2017-20149Security
CVE-2017-20149

Critical vulnerability in the RouterOS web server

CVE-2017-20149 is a critical vulnerability (CVSS 9.8) in the RouterOS web server that allows an unauthenticated remote user to execute arbitrary code. It affects versions prior to 6.37.5 and 6.38.5. You must immediately update the firmware to a later version to eliminate the risk.

Critical · 9.8
Illustrazione per CVE-2020-5721Security
CVE-2020-5721

Plaintext password in the WinBox configuration file

WinBox 3.22 and earlier versions save the user password in unencrypted text in the configuration file if the "Keep Password" option is enabled and no Master Password is set. Since these are the default settings, an attacker with access to the file can recover the credentials to access the router. You must update WinBox to a later version or disable the password saving option.

Medium · 5.5
Illustrazione per CVE-2020-5720Security
CVE-2020-5720

Path traversal vulnerability in WinBox

CVE-2020-5720 is a path traversal vulnerability in WinBox, the graphical client for managing MikroTik routers. It affects all WinBox versions prior to 3.21 and allows the creation of arbitrary files if the client connects to a malicious endpoint or suffers a man-in-the-middle attack. To mitigate the risk, you must update WinBox to version 3.21 or higher and restrict access to the service only from the trusted administration network.

Medium · 5.9
Illustrazione per CVE-2019-3981Security
CVE-2019-3981

Winbox Vulnerability: Man-in-the-Middle Attack

CVE-2019-3981 is a vulnerability in MikroTik Winbox 3.20 and earlier that allows an attacker positioned between the client and the router to perform an authentication downgrade and retrieve the username and MD5-hashed password. The risk arises when Winbox is reachable from untrusted networks. To mitigate the risk, you must update Winbox to a version later than 3.20 and restrict access to the service to the administration network only.

Low · 3.7