ZeroHour

CVE-2018-14847

KEV PoC ×7mass

Directory Traversal in MikroTik RouterOS Winbox Interface (Unauthenticated File Read)

CISA: MikroTik Router OS Directory Traversal Vulnerability

CVSS 3.1
9.1 critical
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2018-14847 is a directory traversal (CWE-22) vulnerability in the Winbox interface of MikroTik RouterOS through version 6.42. An unauthenticated remote attacker can send crafted Winbox requests that traverse directories to read arbitrary files on the device, while authenticated attackers can also write arbitrary files. By reading files an attacker can retrieve sensitive device data such as stored credentials or configuration, and file write capability can support further compromise of the router. Any MikroTik router or device running RouterOS at or below 6.42 with the Winbox interface reachable is affected, which includes large numbers of internet-exposed edge and ISP devices. The flaw is actively exploited: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-12-01), has multiple public PoCs, and compromised MikroTik routers have been used by threats such as Trickbot (as C2 proxies) and the Mēris botnet, with public scans reporting over 300,000 vulnerable devices.

What to do: Apply MikroTik's updates per vendor instructions, moving RouterOS above version 6.42, prioritizing devices with Winbox reachable from untrusted networks. Until patched, restrict or disable Winbox access from WAN/untrusted interfaces to limit unauthenticated file reads. Given known botnet abuse of this flaw, check devices for signs of compromise and rotate credentials that may have been exposed via file reads.

Affected
mikrotik routerosthrough 6.42 (all versions at or below 6.42)
Estimated exposure
mass≈300,000+ internet-exposed MikroTik devices — Related public coverage reports internet-wide scans finding over 300,000 vulnerable MikroTik devices, and RouterOS is widely deployed on internet-facing edge and ISP equipment, so the exposed population is plausibly at or above that order…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

CISA Known Exploited Vulnerability
Affected
MikroTik RouterOS
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
mikrotik
Products
routeros
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news