MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
References
Link Resource
https://github.com/BasuCert/WinboxPoC Exploit Mitigation Third Party Advisory
https://github.com/BigNerd95/WinboxExploit Exploit Mitigation Third Party Advisory
https://github.com/tenable/routeros/blob/master/bug_hunting_in_routeros_derbycon_2018.pdf Exploit Third Party Advisory
https://github.com/tenable/routeros/tree/master/poc/bytheway Exploit Third Party Advisory
https://github.com/tenable/routeros/tree/master/poc/cve_2018_14847 Exploit Third Party Advisory
https://n0p.me/winbox-bug-dissection/ Exploit Third Party Advisory
https://www.exploit-db.com/exploits/45578/ Exploit Third Party Advisory VDB Entry
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2018-08-02T07:00:00

Updated: 2018-11-16T17:57:02

Reserved: 2018-08-02T00:00:00


Link: CVE-2018-14847

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-08-02T07:29:00.280

Modified: 2019-03-07T14:12:53.707


Link: CVE-2018-14847

JSON object: View

cve-icon Redhat Information

No data.

CWE