CISA Known Exploited Vulnerability

CVE-2018-14847

MikroTik · RouterOS

MikroTik Router OS Directory Traversal Vulnerability

Date added
BOD 22-01 due date
CWE CWE-22
Ransomware Unknown

CISA description

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Required action

Apply updates per vendor instructions.