← KEV catalog
CISA known exploited vulnerability

CVE-2018-14847

MikroTik Router OS Directory Traversal Vulnerability

SOURCE FACT

MikroTik · RouterOS

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Required action

Apply updates per vendor instructions.

CISA notes

https://nvd.nist.gov/vuln/detail/CVE-2018-14847

View source evidence →

CHECK YOUR OUTSIDE-IN INVENTORY

Could this product be present?