vulnerability

MikroTik RouterOS: CVE-2018-14847: Improper Limitation of a Pathname to a Restricted Directory

Severity
6
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:N)
Published
Aug 2, 2018
Added
May 2, 2025
Modified
May 5, 2025

Description

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Solution

mikrotik-routeros-upgrade-to-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.