Junglewise Threat Intelligence

CVE-2026-67281: MikroTik RouterOS WebFig uninitialized pointer file read

CVE-2026-67281 · Severity: high · CVSS 7.5 · Published 2026-09-05

Technologies: MikroTik RouterOS. Vendors: MikroTik.

Executive brief

MikroTik RouterOS WebFig is a web interface for managing router devices. This vulnerability allows an attacker without authentication to read sensitive files on the device, including configuration data and credentials, by exploiting a memory management flaw in the file-serving path.

Technical details

CVE-2026-67281 is an access of uninitialized pointer (CWE-824) in RouterOS WebFig's /jsproxy path. An unauthenticated network attacker can exploit heap allocation timing to cause the file authorization logic to dereference a stale principal pointer with elevated privileges, then supply path traversal components in an encrypted URI to escape the WebFig namespace and read root-owned files.

Affected products

  • MikroTik RouterOS 7.20 to 7.23.3, 7.24.0 to 7.24.1

Timeline

  • 2026-09-05: disclosed
  • 2026-09-05: patched: Fixed in RouterOS 7.23.4 (Long-term) and 7.24.2 (Stable)

References

Related threats