Skip to main content
All vulnerabilities
CVE-2018-14847

MikroTik Router OS Directory Traversal Vulnerability

MikroTikRouterOS

Added to KEV catalog
1 December 2021
Federal remediation due date
1 June 2022
Weakness classification (CWE)
CWE-22

CISA Description

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Required action

Apply updates per vendor instructions.

Notes

https://nvd.nist.gov/vuln/detail/CVE-2018-14847

Confirm Your Exposure

Is this vulnerability present in your environment?

CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.

Explore VAPT Services
CVE-2018-14847: MikroTik Router OS Directory | CRS