Junglewise Threat Intelligence

CVE-2025-56566: MikroTik firmware cleartext credential storage

CVE-2025-56566 · Severity: medium · CVSS 4.6 · Published 2026-09-16

Executive brief

MikroTik routers running firmware 7.19.4 store administrative passwords, dynamic DNS credentials, and SMB user accounts in unencrypted form on the device's flash memory. An attacker with physical access to the hardware can extract this flash memory and recover all stored credentials and network information, compromising external services and enabling reconnaissance of the internal network—a critical risk for devices in unattended or physically unsecured locations.

Technical details

MikroTik firmware 7.19.4 stores sensitive configuration data—including administrative credentials, dynamic DNS passwords, SMB user accounts, and DHCP lease records—in cleartext within non-volatile SPI flash memory (CWE-312, CWE-316). The vulnerability requires physical access to the device and can be exploited by attaching a commodity SPI flash programmer (e.g., CH341A) to read the entire flash contents without authentication or powering the device. Extracted plaintext strings reveal credentials for external services, active network hosts and MAC addresses, and internal authentication accounts. An attacker can then use these credentials to compromise dependent services, map the internal network, and establish a foothold—extending the impact beyond the router itself to downstream systems and infrastructure.

Affected products

  • MikroTik RouterOS 7.19.4

Timeline

  • 2025-07-28: disclosed: Vulnerability discovered
  • 2025-08-01: disclosed: Technical validation completed
  • 2025-08-02: disclosed: Vendor notified
  • 2025-08-28: disclosed: CVE ID assigned by MITRE
  • 2026-08-14: disclosed: Public disclosure

References

Related threats