Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 30 Oct 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in MikroTik RouterOS v.7.14.2 and SwitchOS v.2.18 allows a remote attacker to execute arbitrary code via the HTTP- only WebFig management component | An issue in MikroTik RouterOS v.7.14.2 and SwOS v.2.18 exposes the WebFig management interface over cleartext HTTP by default, allowing an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept credentials. |
Mon, 27 Oct 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mikrotik
Mikrotik routeros Mikrotik switchos |
|
| Vendors & Products |
Mikrotik
Mikrotik routeros Mikrotik switchos |
Mon, 27 Oct 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-1188 CWE-200 CWE-319 |
|
| Metrics |
cvssV3_1
|
Mon, 27 Oct 2025 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in MikroTik RouterOS v.7.14.2 and SwitchOS v.2.18 allows a remote attacker to execute arbitrary code via the HTTP- only WebFig management component | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-10-30T17:24:08.770Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-61481
Updated: 2025-10-27T15:50:04.982Z
Status : Deferred
Published: 2025-10-27T14:15:41.410
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-61481
No data.
OpenCVE Enrichment
Updated: 2025-10-27T22:09:48Z