PT-2025-43960 · Mikrotik · Mikrotik Routeros+1
Published
2025-10-15
·
Updated
2025-11-30
·
CVE-2025-61481
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
MikroTik RouterOS version 7.14.2
MikroTik SwitchOS version 2.18
Description
An issue exists in MikroTik RouterOS and SwitchOS where the WebFig management interface is exposed over cleartext HTTP by default. This allows a remote attacker to potentially intercept credentials through man-in-the-middle attacks or execute injected JavaScript in the administrator’s browser. The vulnerability allows for remote code execution via the HTTP-only WebFig management component. Approximately 7.3 million devices are estimated to be vulnerable. The vulnerability allows an attacker to intercept credentials and potentially gain full system compromise. The
WebFig interface is the component affected.Recommendations
For MikroTik RouterOS version 7.14.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For MikroTik SwitchOS version 2.18, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Information Disclosure
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mikrotik Routeros
Mikrotik Switchos