CVE-2018-14847: MikroTik Router OS Directory Traversal Vulnerability
Critical severity, CVSS 9.1. Actively exploited: in CISA KEV since 2021-12-01. EPSS: 96% chance of exploitation in the next 30 days.
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Affected products
- MikroTik RouterOS: up to and including 6.42
Published 2018-08-02. Last modified 2026-06-17.