AI description
Automated description summarized from trusted sources.
CVE-2018-14847 is a directory traversal vulnerability found in MikroTik RouterOS, affecting versions up to 6.42, specifically within its WinBox interface. This flaw allows unauthenticated remote attackers to read arbitrary files from affected devices. Additionally, authenticated remote attackers can exploit this vulnerability to write arbitrary files. Further research revealed that this vulnerability could be leveraged to achieve remote code execution and gain root access on compromised MikroTik routers. Attackers could exploit this to steal administrator credentials and deploy malware payloads.
- Description
- MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
- Source
- cve@mitre.org
- NVD status
- Analyzed
- Products
- routeros
CVSS 3.1
- Type
- Primary
- Base score
- 9.1
- Impact score
- 5.2
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
Data from CISA
- Vulnerability name
- MikroTik Router OS Directory Traversal Vulnerability
- Exploit added on
- Dec 1, 2021
- Exploit action due
- Jun 1, 2022
- Required action
- Apply updates per vendor instructions.
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*",
"matchCriteriaId": "16E5E5C5-AE57-4E80-8405-C12C6D0999EB",
"versionEndIncluding": "6.42",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]