← Back to browse · API

CVE-2018-14847

Severity
CRITICAL
CVSS
9.1
EPSS
0.96087
Risk score
58.63
CISA KEV
Yes
PoC
No
Published
2018-08-02
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2018-6729, GHSA-J583-4CFP-XF9M
Products
MikroTik:RouterOS, n/a:n/a n/a
Sources
cisa.gov CVE-2018-14847
euvd EUVD-2018-6729

Description

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

References