Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-14847

98
FAUCET Score

CVE-2018-14847 is a critical directory traversal vulnerability in MikroTik RouterOS through version 6.42, specifically affecting the WinBox interface. This flaw allows unauthenticated remote attackers to read arbitrary files and authenticated remote attackers to write arbitrary files. With a CVSS score of 9.1 (CRITICAL) and an EPSS score of 0.92843, it presents a severe risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality and integrity. This vulnerability is actively exploited in the wild, with public exploit code available (e.g., Metasploit, ExploitDB) and significant community discussion, including recent observations of increased exploitation attempts.

Impacted Technologies

VendorProductVersion(s)CPE
<= 6.42CPE matchmatch criteria
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.1CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
3.9
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
96.09%
Probability of exploitation in next 30 days
EPSS Percentile
99.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Added to KEV · Dec 1, 2021
Metasploit: Mikrotik Winbox Arbitrary File Read · Aug 2, 2018
ExploitDB: EDB-45578 · Oct 10, 2018
This CVE's current EPSS score of 0.9609 is in the 99th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryworkaround availablevia nvd_reference
View patch

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
github.com / BasuCert/WinboxPoC
ExploitMitigationThird Party Advisory
github.com / BigNerd95/WinboxExploit
ExploitMitigationThird Party Advisory
github.com / tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdf
Broken LinkExploitThird Party Advisory
github.com / tenable/routeros/tree/master/poc/bytheway
ExploitThird Party Advisory
github.com / tenable/routeros/tree/master/poc/cve_2018_14847
ExploitThird Party Advisory
mikrotik.com / supportsec/winbox-vulnerability
Vendor Advisory
n0p.me / winbox-bug-dissection
ExploitThird Party Advisory
exploit-db.com / exploits/45578
ExploitThird Party AdvisoryVDB Entry