The calculated severity for CVEs has been updated to use CVSS v3 by default. CVEs that do not have a CVSS v3 score will fall back CVSS v2 for calculating severity. Severity display preferences can be toggled in the settings dropdown.
RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell could be enabled.
Base Score: 6.5
Impact Score: 6.4
Exploitability Score: 8
Base Score: 8.8
Impact Score: 5.9
Exploitability Score: 2.8
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* versions up to 6.45.6 (inclusive)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* versions up to 6.44.5 (inclusive)