CVE-2025-56566

MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password.
CVSS

No CVSS.

Configurations

No configuration.

History

16 Sep 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 21:17

Updated : 2026-09-16 21:17


NVD link : CVE-2025-56566

Mitre link : CVE-2025-56566

CVE.ORG link : CVE-2025-56566


JSON object : View

Products Affected

No product.

CWE

No CWE.