CVE-2019-3976: Path Traversal
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell could be enabled.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3976?
CVE-2019-3976 is considered a high severity vulnerability due to its potential to allow unauthorized directory creation.
How do I fix CVE-2019-3976?
To fix CVE-2019-3976, update RouterOS to a version above 6.45.6 or 6.44.5 Long-term.
What are the affected versions in CVE-2019-3976?
The affected versions of RouterOS in CVE-2019-3976 are 6.45.6 Stable and 6.44.5 Long-term and below.
Who is impacted by CVE-2019-3976?
Any authenticated user of MikroTik devices running the affected versions is at risk of exploitation from CVE-2019-3976.
What type of vulnerability is CVE-2019-3976?
CVE-2019-3976 is an arbitrary directory creation vulnerability associated with the upgrade package's name field.