
WinBox and WebFig
WinBox, WebFig, and the router’s web management service: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

MikroTik Safe Mode: How RouterOS’s Safety Net Works
Safe Mode is RouterOS's safety net: while it is active, the router logs every change and, if the session that made them drops, it rolls them back automatically. You enable it with Ctrl+X (or F4) in the terminal and with the Safe Mode button in WinBox. It holds up to 100 actions and does not cover commands that restart the router.
LabCVE-2018-14847: Recovering plaintext passwords from user.dat on RouterOS v6
We reproduced the CVE-2018-14847 vulnerability on RouterOS v6, confirming that an unauthenticated attacker can read the user.dat file and recover plaintext passwords due to a weak XOR transformation. The issue is fixed in versions 6.40.8, 6.42.11, and 6.49.7, where access to the file is denied.
FirmwareRouterOS 6.49.23 long-term: CVE-2026-84411 fix
MikroTik has released version 6.49.23 of the long-term channel for RouterOS 6. The update includes a critical security fix (CVE-2026-84411) and system stability improvements. Installation is recommended on all production devices using the conservative branch, after creating a full backup.
SecurityCritical vulnerability in RouterOS web service
CVE-2026-84411 is a critical vulnerability (CVSS 9.8) in the RouterOS management web service that allows an unauthenticated attacker to execute arbitrary code as root or cause a denial of service. All RouterOS versions below 7.24 are affected. The immediate action is to update the firmware to version 7.24 or later and restrict access to the web service to trusted networks only.
SecurityUnauthorized file read in WebFig
CVE-2026-67281 is an unauthenticated file read vulnerability in the WebFig service of RouterOS that allows an attacker to access restricted files, including credential databases. It affects 7.x versions lower than 7.23.4 and 7.24.2. You must update the firmware or disable remote access to WebFig.
SecurityWebFig Exposed in Clear on RouterOS and SwOS
CVE-2025-61481 exposes the WebFig management interface of RouterOS v.7.14.2 and SwOS v.2.18 via unencrypted HTTP, allowing a man-in-the-middle attacker to inject JavaScript into the administrator's browser and intercept credentials. The vulnerability is classified as critical with a CVSS score of 10.0. To mitigate the risk, disable WebFig if not necessary or restrict access exclusively to the trusted management network.
SecurityAccount Enumeration in Winbox on RouterOS
CVE-2024-54772 allows an attacker to identify valid usernames on a MikroTik router by analyzing differences in Winbox service response times. Affected versions include long-term 6.43.13 through 6.49.13 and stable 6.43 through 7.17.2. To mitigate the risk, upgrade to version 6.49.18 or later and restrict Winbox access to the management network.
SecurityHeap corruption in RouterOS 6 WebFig
CVE-2023-30800 is a heap memory corruption flaw in the web server of RouterOS version 6. An unauthenticated remote attacker can crash the web interface by sending a malicious HTTP request. The vulnerability is fixed in stable version 6.49.10; RouterOS version 7 is not affected.
SecurityArbitrary code execution on RouterOS
CVE-2023-30799 is a privilege escalation vulnerability that allows an authenticated attacker with an admin account to obtain super-admin privileges and execute arbitrary code. It affects stable versions of RouterOS prior to 6.49.7 and long-term versions up to and including 6.48.6. Updating to a patched version is the primary measure to mitigate the risk.
SecurityCritical vulnerability in the RouterOS web server
CVE-2017-20149 is a critical vulnerability (CVSS 9.8) in the RouterOS web server that allows an unauthenticated remote user to execute arbitrary code. It affects versions prior to 6.37.5 and 6.38.5. You must immediately update the firmware to a later version to eliminate the risk.
SecurityPlaintext password in the WinBox configuration file
WinBox 3.22 and earlier versions save the user password in unencrypted text in the configuration file if the "Keep Password" option is enabled and no Master Password is set. Since these are the default settings, an attacker with access to the file can recover the credentials to access the router. You must update WinBox to a later version or disable the password saving option.
SecurityPath traversal vulnerability in WinBox
CVE-2020-5720 is a path traversal vulnerability in WinBox, the graphical client for managing MikroTik routers. It affects all WinBox versions prior to 3.21 and allows the creation of arbitrary files if the client connects to a malicious endpoint or suffers a man-in-the-middle attack. To mitigate the risk, you must update WinBox to version 3.21 or higher and restrict access to the service only from the trusted administration network.
SecurityWinbox Vulnerability: Man-in-the-Middle Attack
CVE-2019-3981 is a vulnerability in MikroTik Winbox 3.20 and earlier that allows an attacker positioned between the client and the router to perform an authentication downgrade and retrieve the username and MD5-hashed password. The risk arises when Winbox is reachable from untrusted networks. To mitigate the risk, you must update Winbox to a version later than 3.20 and restrict access to the service to the administration network only.