MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NMikrotik Routeros
OSMikrotik≤ 6.42
CISA KEV — detailsi
- Vendori
- MikroTik
- Producti
- RouterOS
- Added to KEVi
- December 1, 2021
- Remediation deadline (US Federal)i
- June 1, 2022(overdue)
Apply updates per vendor instructions.
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Related vulnerabilities
MikroTik RouterOS SMB — buffer overflow przed uwierzytelnieniem (RCE)
MikroTik RouterOS — privilege escalation admin do super-admin z możliwością RCE
MikroTik RouterOS — RCE przez uszkodzenie pamięci w serwerze WWW (Chimay-Red)
MikroTik RouterOS: path traversal przez symlinki w pakiecie container
Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote atta...