Skip to content
COOEY

EXPOSURES › CVE-2018-14847

CVE-2018-14847

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-12-01 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-14847 ↗
⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatched

MikroTik RouterOS 6.42 allows unauthenticated remote attackers to read arbitrary files and authenticated attackers to write arbitrary files via directory traversal in the WinBox interface.

This directory traversal flaw in MikroTik RouterOS exposes sensitive data and enables file manipulation, directly impacting DIB networks reliant on network infrastructure. The vulnerability is actively exploited (KEV catalog), meaning organizations must patch immediately to prevent data exfiltration and unauthorized system changes. DIB compliance requires continuous monitoring and rapid patching of such known, exploited flaws to avoid FCA settlements and maintain security posture.

Shame score — A directory traversal vulnerability in widely deployed router firmware that allows unauthenticated file reads and authenticated file writes, and is actively exploited in the wild, represents a severe, avoidable failure in securing critical network infrastructure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.