Vulnerability Description
MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this material from an SPI flash dump, without authenticating to the device and without knowledge of the administrative password.
References
FAQ
What is CVE-2025-56566?
CVE-2025-56566 is a documented vulnerability. MikroTik firmware 7.19.4 stores sensitive authentication credentials and network state in cleartext within non-volatile storage. An attacker with physical access to the device can extract this materia...
How severe is CVE-2025-56566?
CVSS scoring is not yet available for CVE-2025-56566. Check NVD for updates.
Is there a patch for CVE-2025-56566?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.