PT-2025-43960 · Mikrotik · Mikrotik Routeros+1

Published

2025-10-15

·

Updated

2025-11-30

·

CVE-2025-61481

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS version 7.14.2 MikroTik SwitchOS version 2.18
Description An issue exists in MikroTik RouterOS and SwitchOS where the WebFig management interface is exposed over cleartext HTTP by default. This allows a remote attacker to potentially intercept credentials through man-in-the-middle attacks or execute injected JavaScript in the administrator’s browser. The vulnerability allows for remote code execution via the HTTP-only WebFig management component. Approximately 7.3 million devices are estimated to be vulnerable. The vulnerability allows an attacker to intercept credentials and potentially gain full system compromise. The WebFig interface is the component affected.
Recommendations For MikroTik RouterOS version 7.14.2, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For MikroTik SwitchOS version 2.18, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Information Disclosure

Cleartext Transmission of Sensitive Information

Weakness Enumeration

Related Identifiers

BDU:2025-13545
CVE-2025-61481

Affected Products

Mikrotik Routeros
Mikrotik Switchos