CVE-2025-61481: Infoleak
An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61481?
CVE-2025-61481 has been rated as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-61481?
To mitigate CVE-2025-61481, update MikroTik RouterOS to version 7.14.3 or later, or SwitchOS to version 2.19 or later.
Who is affected by CVE-2025-61481?
CVE-2025-61481 affects MikroTik RouterOS version 7.14.2 and SwitchOS version 2.18.
What type of attack is associated with CVE-2025-61481?
CVE-2025-61481 involves remote attackers executing arbitrary code through the HTTP-only WebFig management component.
When was CVE-2025-61481 disclosed?
CVE-2025-61481 was disclosed in relation to vulnerabilities found in MikroTik software as of 2025.