Unrated severityCISA KEVNVD Advisory· Published Aug 2, 2018· Updated Oct 21, 2025
CVE-2018-14847
CVE-2018-14847
Description
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6- www.exploit-db.com/exploits/45578/mitreexploit
- github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdfmitre
- github.com/tenable/routeros/tree/master/poc/bythewaymitre
- github.com/tenable/routeros/tree/master/poc/cve_2018_14847mitre
- mikrotik.com/supportsec/winbox-vulnerabilitymitre
- n0p.me/winbox-bug-dissection/mitre
News mentions
0No linked articles in our index yet.