First published: Fri Mar 19 2021(Updated: )
** DISPUTED ** MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | =6.47.9 | |
=6.47.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27221 is a vulnerability in MikroTik RouterOS 6.47.9 that allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command.
CVE-2021-27221 has a severity rating of 8.1 (high).
CVE-2021-27221 affects MikroTik RouterOS 6.47.9.
An attacker can exploit CVE-2021-27221 by using remote authenticated ftp access to create or overwrite .rsc files using the /export command.
At the time of writing, there is no official fix or patch available for CVE-2021-27221.