VYPR
High severity8.1NVD Advisory· Published Mar 19, 2021· Updated Jun 17, 2026

CVE-2021-27221

CVE-2021-27221

Description

MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work

Affected products

3
  • Mikrotik/Routeros2 versions
    cpe:2.3:o:mikrotik:routeros:6.47.9:*:*:*:-:*:*:*+ 1 more
    • cpe:2.3:o:mikrotik:routeros:6.47.9:*:*:*:-:*:*:*
    • (no CPE)range: 6.47.9
  • MikroTik/RouterOSdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.