Junglewise Threat Intelligence

CVE-2018-14847: MikroTik Router OS Directory Traversal Vulnerability

CVE-2018-14847 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2021-12-01

Technologies: MikroTik RouterOS. Vendors: MikroTik.

Executive brief

A directory traversal vulnerability in the WinBox interface of MikroTik RouterOS allows unauthenticated remote attackers to read arbitrary files and authenticated attackers to write arbitrary files. The vulnerability has been actively exploited in the wild.

Affected products

  • MikroTik RouterOS through 6.42

Timeline

  • 2018-08-02: disclosed: Initial vulnerability disclosure and exploit availability (based on reference dates)
  • 2021-12-01: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats