MikroTik RouterOS Winbox Unauthenticated Arbitrary File Read/Write Vulnerability

Critical Nessus Plugin ID 117335


The remote networking device is affected by an unauthenticated arbitrary file read/write vulnerability.


The remote networking device is running a version of MikroTik RouterOS vulnerable to an unauthenticated arbitrary file read and write vulnerability. An unauthenticated attacker could leverage this vulnerability to read or write protected files on the affected host.
Nessus was able to exploit this vulnerability to retrieve the device credential store.


Upgrade to MikroTik RouterOS 6.40.8 / 6.42.1 / 6.43rc4 or later.

See Also





Plugin Details

Severity: Critical

ID: 117335

File Name: mikrotik_cve_2018-14847.nasl

Version: 1.4

Type: remote

Family: Misc.

Published: 2018/09/06

Updated: 2019/04/05

Dependencies: 59731

Risk Information

Risk Factor: Critical

CVSS Score Source: manual

CVSS Score Rationale: Vulnerability allows reads and writes to the file system

CVSS v2.0

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

CVSS v3.0

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2018/04/23

Vulnerability Publication Date: 2018/04/23

Reference Information

CVE: CVE-2018-14847