CVE Feed

    Dashboard / CVE / CVE-2018-14847

    CVE-2018-14847

    MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

    Published:Aug 2, 2018
    Last Modified:Nov 7, 2025
    EPS:Aug 2, 2018
    EPSS Score:0.92843
    CVSS Score:9.1

    CISA Notification

    Description

    MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

    Required Action:

    Apply updates per vendor instructions.

    Notes:

    No extra notes provided.

    Due Date
    Jun 1, 2022
    1563 days ago
    Alert Date
    Dec 1, 2021
    1745 days ago

    Affected Products

    Vendor
    Mikrotik
    Product
    Routeros

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High