CVE-2021-27221: High severity mikrotik routeros vulnerability
Published Mar 19, 2021
·Updated
DISPUTED MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work.
Affected Software
1 affected component
Mikrotik RouterOS=6.47.9
Event History
Mar 19, 2021
CVE Published
via MITRE·02:28 AM
Data Sourced
via MITRE·02:28 AM
Description
Disputed
03:15 AM
Frequently Asked Questions
1
What is CVE-2021-27221?
CVE-2021-27221 is a vulnerability in MikroTik RouterOS 6.47.9 that allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command.
2
What is the severity of CVE-2021-27221?
CVE-2021-27221 has a severity rating of 8.1 (high).
3
How does CVE-2021-27221 affect MikroTik RouterOS?
CVE-2021-27221 affects MikroTik RouterOS 6.47.9.
4
How can an attacker exploit CVE-2021-27221?
An attacker can exploit CVE-2021-27221 by using remote authenticated ftp access to create or overwrite .rsc files using the /export command.
5
Is there a fix for CVE-2021-27221?
At the time of writing, there is no official fix or patch available for CVE-2021-27221.