SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2018-14847

MikroTik Router OS Directory Traversal Vulnerability

KEVCRITICAL 9.1EPSS 96.1%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

CVSS 3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
96.09% probability · 100th percentile
CISA KEV
Listed 1 December 2021 · due 1 June 2022
Weakness
CWE-22
Affected
mikrotik/routeros
Source
cve@mitre.org

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-14847

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.