Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-67281— Unauthenticated file read in Mikrotik RouterOS

Quick assessment

Affected
Mikrotik RouterOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

RouterOS WebFig 存在一个未认证的文件读取漏洞,位于 路径。新分配的会话中保留了一个过期的、未初始化的 principal 指针,该指针用于文件授权。未认证的 attacker(攻击者)可以通过操纵内存分配器,使得文件服务路径以足够权限解引用该指针;随后,通过构造包含父目录组件的加密 URI,攻击者可以跳出 WebFig 的文件命名空间,从而泄露由 root 用户拥有的文件,包括包含凭据的配置文件。该问题已在以下版本中修复:6.49.21(长期支持版)、7.23.4(长期支持版)和 7.24.2(稳定

CVSS 8.7 · High EPSS 0.46% · P38

Affected Version Matrix 3

VendorProduct Version RangeStatus
Mikrotik RouterOS 7.24< 7.24.2 affected
7.0.0< 7.23.4 affected
6.0.0< 6.49.21 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-67281

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Unauthenticated file read in Mikrotik RouterOS
Source: CVE Program / CVE List V5
Vulnerability Description
RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials.This issue was fixed in versions: 6.49.21 (Long-term), 7.23.4 (Long-term) and 7.24.2 (Stable)
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
使用未经初始化的指针
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Mikrotik RouterOS 7.24 ~ 7.24.2 -

II. Public POCs for CVE-2026-67281

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-67281

登录查看更多情报信息。

Security Blog Posts for CVE-2026-67281 (3)

Vendor Pages for CVE-2026-67281 (4)

Same Patch Batch · Mikrotik · 2026-09-05 · 6 CVEs total

CVE-2026-86060 9.2 CRITICAL SSH session privilege manipulation via a crafted username in Mikrotik RouterOS
CVE-2026-67276 9.2 CRITICAL SSH user impersonation possible in Mikrotik RouterOS
CVE-2026-67277 8.8 HIGH Kernel memory disclosure and denial of service in MikroTik RouterOS btest service
CVE-2026-67279 6.9 MEDIUM SSH Pre-Authentication Rekey State Bypass in MikroTik RouterOS
CVE-2026-67278 6.3 MEDIUM TLS server impersonation possible in Mikrotik RouterOS

IV. Related Vulnerabilities

V. Comments for CVE-2026-67281

No comments yet


Leave a comment