MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has write permissions. WinBox is vulnerable to this attack if it connects to a malicious endpoint or if an attacker mounts a man in the middle attack.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NMikrotik Winbox
OSMikrotik< 3.21
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
Related vulnerabilities
CVE-2020-5721MEDIUM5.5same product
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file...
CVE-2019-3981LOW3.7same product
MikroTik Winbox w wersji 3.20 i niższych jest podatny na ataki man in the middle. Atakujący pośrodkujący połąc...
CVE-2018-14847CRITICAL9.1⚠ KEVPL ✓same vendor
MikroTik RouterOS — path traversal w interfejsie WinBox (odczyt/zapis plików)
CVE-2018-7445CRITICAL9.8⚠ KEVPL ✓same vendor
MikroTik RouterOS SMB — buffer overflow przed uwierzytelnieniem (RCE)
CVE-2023-30799CRITICAL9.1PL ✓same vendor
MikroTik RouterOS — privilege escalation admin do super-admin z możliwością RCE