VYPR

WebFig

by Mikrotik

CVEs (1)

  • CVE-2026-67281HigSep 5, 2026
    risk 0.49cvss 7.5epss 0.01

    RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving…