CVE-2018-14847 is a critical directory traversal vulnerability in MikroTik RouterOS through version 6.42, specifically affecting the WinBox interface. This flaw allows unauthenticated remote attackers to read arbitrary files and authenticated remote attackers to write arbitrary files. With a CVSS score of 9.1 (CRITICAL) and an EPSS score of 0.92843, it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality and integrity. This vulnerability is actively exploited in the wild, with public exploit code available (e.g., Metasploit, ExploitDB) and significant community discussion, including recent observations of increased exploitation attempts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.42CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.