CVE-2018-14847

CRITICAL KEV

MikroTik RouterOS <6.42 - Path Traversal

Title source: llm

Description

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Exploits (18)

nomisec WORKING POC 519 stars
by BasuCert · remote
https://github.com/BasuCert/WinboxPoC
nomisec WORKING POC 55 stars
by hacker30468 · infoleak
https://github.com/hacker30468/Mikrotik-router-hack
nomisec WORKING POC 30 stars
by jas502n · remote
https://github.com/jas502n/CVE-2018-14847
nomisec WORKING POC 20 stars
by sinichi449 · remote
https://github.com/sinichi449/Python-MikrotikLoginExploit
nomisec WORKING POC 15 stars
by syrex1013 · infoleak
https://github.com/syrex1013/MikroRoot
nomisec WORKING POC 7 stars
by msterusky · remote
https://github.com/msterusky/WinboxExploit
nomisec WORKING POC 6 stars
by mahmoodsabir · infoleak
https://github.com/mahmoodsabir/mikrotik-beast
nomisec WORKING POC 5 stars
by K3ysTr0K3R · remote
https://github.com/K3ysTr0K3R/CVE-2018-14847-EXPLOIT
nomisec WORKING POC 4 stars
by babyshen · remote
https://github.com/babyshen/routeros-CVE-2018-14847-bytheway
nomisec WORKING POC 1 stars
by Tr33-He11 · infoleak
https://github.com/Tr33-He11/winboxPOC
nomisec WORKING POC 1 stars
by tausifzaman · infoleak
https://github.com/tausifzaman/CVE-2018-14847
nomisec WORKING POC 1 stars
by yukar1z0e · remote
https://github.com/yukar1z0e/CVE-2018-14847
gitlab WORKING POC
by Krusth · infoleak
https://gitlab.com/Krusth/WinboxPoC
gitlab WORKING POC
by neurosatan · remote
https://gitlab.com/neurosatan/WinboxPoC
vulncheck_xdb WORKING POC
remote
https://github.com/k8gege/LadonGo
exploitdb WORKING POC
by Jacob Baines · c++remotehardware
https://www.exploit-db.com/exploits/45578
vulncheck_xdb WORKING POC
remote
https://github.com/threat9/routersploit
vulncheck_xdb SCANNER
remote
https://github.com/tenable/routeros

Scores

CVSS v3 9.1
EPSS 0.9284
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Exploitation Intel

CISA KEV 2021-12-01
VulnCheck KEV 2020-12-01
InTheWild.io 2021-12-01
ENISA EUVD EUVD-2018-6729

Classification

CWE
CWE-22
Status published

Affected Products (1)

mikrotik/routeros < 6.42

Timeline

Published Aug 02, 2018
KEV Added Dec 01, 2021
Tracked Since Feb 18, 2026