Description
An issue in MikroTik RouterOS v.7.14.2 and SwitchOS v.2.18 allows a remote attacker to execute arbitrary code via the HTTP- only WebFig management component
References
help.mikrotik.com/docs/spaces/ROS/pages/328131/WebFig
help.mikrotik.com/docs/spaces/SWOS/pages/328415/SwOS
svarthatt.se/cve/mikrotik-swos-cve-2025-61481/