Cleartext Authentication Credentials Vulnerability in MikroTik Firmware
CVE-2025-56566

4.6MEDIUM

Key Information:

Vendor

MikroTik

Vendor
CVE Published:
16 September 2026

What is CVE-2025-56566?

The MikroTik firmware version 7.19.4 contains a clearance vulnerability that allows sensitive authentication credentials and network state information to be stored unencrypted in non-volatile memory. An attacker who physically accesses the affected device can retrieve these sensitive details through an SPI flash dump, circumventing the need for authentication or knowledge of the administrative password. This poses significant security risks for users, as the exposed data can be exploited to gain unauthorized access to network resources or sensitive information.

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.