A AegiFlow
UNKNOWNKNOWN EXPLOITED

CVE-2018-14847

MikroTik Router OS Directory Traversal Vulnerability

Published
2021-12-01
Modified
2026-07-31
Sources
cisa-kev

Summary

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.