First published: Thu Aug 02 2018(Updated: )
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | <=6.42 | |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-14847.
The severity of CVE-2018-14847 is critical with a CVSS score of 9.1.
CVE-2018-14847 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
MikroTik RouterOS up to version 6.42 is affected by CVE-2018-14847.
Yes, MikroTik has released a fix for CVE-2018-14847. It is recommended to update to the latest version of MikroTik RouterOS.