Risk Summary
Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation and decryption of all associated traffic.
CVEs (1)
Remediations
- MikroTik recommends administrators to ensure that when a user's permissions are downgraded, the affected user is fully logged out so the new policy can take effect.
- For more information, contact MikroTik (https://mikrotik.com/support).
Affected Vendors
MikroTik
Affected Products (1)
MikroTik
·
RouterOS
vers:all/*
Affected Sectors
Information Technology
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more