VulnerabilityAnalyzed
CVE-2018-14847
MikroTik Router OS Directory Traversal Vulnerability
KEVCRITICAL 9.1EPSS 96.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 1 June 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 96.09% probability · 100th percentile
- CISA KEV
- Listed 1 December 2021 · due 1 June 2022
- Weakness
- CWE-22
- Affected
- mikrotik/routeros
- Source
- cve@mitre.org
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2018-14847
References
- https://github.com/BasuCert/WinboxPoCExploit, Mitigation, Third Party Advisory
- https://github.com/BigNerd95/WinboxExploitExploit, Mitigation, Third Party Advisory
- https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdfBroken Link, Exploit, Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/bythewayExploit, Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/cve_2018_14847Exploit, Third Party Advisory
- https://mikrotik.com/supportsec/winbox-vulnerabilityVendor Advisory
- https://n0p.me/winbox-bug-dissection/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45578/Exploit, Third Party Advisory, VDB Entry
- https://github.com/BasuCert/WinboxPoCExploit, Mitigation, Third Party Advisory
- https://github.com/BigNerd95/WinboxExploitExploit, Mitigation, Third Party Advisory
- https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdfBroken Link, Exploit, Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/bythewayExploit, Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/cve_2018_14847Exploit, Third Party Advisory
- https://n0p.me/winbox-bug-dissection/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/45578/Exploit, Third Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-14847US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.