LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-14847: MikroTik Router OS Directory Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 1, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jun 1, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-14847 to its Known Exploited Vulnerabilities catalog on Dec 1, 2021, with a federal patch deadline of Jun 1, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in…

CVE-2018-14847 is a directory traversal vulnerability in MikroTik RouterOS that affects the WinBox interface. According to the CISA summary, MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files. For organizations that rely on these devices for routing and edge connectivity, this matters because successful abuse can expose configuration and credential material or allow unauthorized changes on the device itself.

Defenders should treat this as a high-priority network infrastructure issue. Confirm exact affected builds, fixed releases, and any additional constraints directly against the vendor advisory, as public detail beyond the CISA summary is limited here.

How it works

The weakness is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory, commonly called path or directory traversal). In this class of flaw, an application fails to properly sanitize user-supplied path elements such as “../” sequences or equivalent encodings. An attacker who can reach the vulnerable interface can craft requests that escape the intended directory and access files elsewhere on the filesystem.

In the case of CVE-2018-14847, the CISA summary states that the vulnerability resides in the WinBox interface of MikroTik RouterOS. Unauthenticated remote attackers can read arbitrary files; attackers who already have valid credentials can write arbitrary files. The summary does not provide packet-level exploit mechanics, specific file paths, or proof-of-concept details; those must be obtained only from authoritative vendor or coordinated disclosure sources if needed for defensive analysis. The practical result is unauthorized disclosure of device files and, for authenticated users, the ability to place or overwrite files on the system.

Am I affected? How to find it in your systems

MikroTik RouterOS commonly runs on MikroTik hardware appliances and on virtual or cloud instances used as routers, firewalls, or CPE devices at branch offices, data-center edges, and small-to-medium business networks. WinBox is the vendor’s management interface and is frequently left reachable on internal or, in misconfigured environments, external networks.

Inventory steps:

Telemetry signs of possible exploitation are general for this vulnerability class: unexpected file-read or file-write activity related to the WinBox process, anomalous inbound connections to the WinBox port from unfamiliar sources, sudden configuration changes, or creation of unfamiliar files or accounts. Because specific indicators of compromise are not supplied in the given facts, treat any suspicious WinBox traffic as warranting deeper forensic review and confirm detection guidance with the vendor.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed RouterOS release from MikroTik’s official channels, validate the package integrity, and schedule installation during a maintenance window that includes a configuration backup and a tested rollback plan. After upgrading, re-verify the version string and confirm that WinBox is running the patched code.

Additional hardening appropriate to this class of flaw and product:

Re-audit the device after remediation to ensure no residual unauthorized files or accounts remain.

If you can't patch immediately

Implement compensating controls while you arrange the upgrade:

These measures reduce exposure but do not eliminate the underlying vulnerability; schedule the official update as soon as possible.

If your data may have been exposed

Actively exploited vulnerabilities on network devices can lead to credential theft, configuration compromise, and subsequent lateral movement or data exposure. Known ransomware use is not documented for this CVE in the supplied facts. If you suspect compromise, isolate the device, preserve logs and memory if feasible, rotate all credentials that may have resided on or traversed the router, and follow your incident-response plan. As a further check, you can run a free exposure scan of your email addresses against known breach data sets to see whether associated accounts have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMikroTik · RouterOS
WeaknessCWE-22
Added to CISA KEVDec 1, 2021
Federal patch deadlineJun 1, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities