CVE-2020-5721
NixOS vulnerability analysis and mitigation

Overview

MikroTik WinBox 3.22 and below contains a vulnerability where the user's cleartext password is stored in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is enabled by default, and by default Master Password is not set. The vulnerability was disclosed on April 15, 2020 and is tracked as CVE-2020-5721 (NVD).

Technical details

The vulnerability exists in the password storage mechanism of WinBox. When the Keep Password option is selected (which is enabled by default), the application stores the user's credentials in cleartext format in a file called settings.cfg.viw located in WinBox's AppData/Roaming directory (C:\Users\USERNAME\AppData\Roaming\Mikrotik\Winbox\settings.cfg.viw). The username and password can be found appended to the keywords 'login' and 'pwd' respectively. The vulnerability has been assigned a CVSS v3.1 base score of 5.5 (Medium) with vector string CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N (Tenable Advisory).

Impact

An attacker who gains access to the configuration file can extract the username and password, which can then be used to gain unauthorized access to the router. This poses a significant security risk as the credentials are stored in plaintext format and can be easily retrieved by anyone with access to the file system (Tenable Advisory).

Exploitability

The vulnerability requires local access to the system where WinBox is installed to exploit. Once an attacker has access to the configuration file, they can easily extract the credentials and use them to pivot to the router (NVD).

Mitigation and workarounds

To mitigate this issue, MikroTik recommends using WinBox's 'Set Master Password' functionality. This feature provides an additional layer of security by encrypting the stored credentials (Tenable Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-78662HIGH7.5
  • Docker logoDocker
  • argo-workflows-fips-4.1
NoYesSep 02, 2026
CVE-2026-56855HIGH7.5
  • Docker logoDocker
  • grafana-13.2
NoYesSep 02, 2026
CVE-2026-84642HIGH7.5
  • NixOS logoNixOS
  • cpe:2.3:a:mozilla:thunderbird
NoYesSep 01, 2026
CVE-2026-84641HIGH7.5
  • NixOS logoNixOS
  • thunderbird
NoYesSep 01, 2026
CVE-2026-32773MEDIUM6.1
  • NixOS logoNixOS
  • spark
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management