← לוח פגיעויות

CVE-2018-14847

קריטית 9.1 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
MikroTik Router OS Directory Traversal Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

מדדים

CVSS 3.1
9.1 (CRITICAL) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS — סבירות ניצול
96% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-22

מוצרים מושפעים

mikrotik: routeros

קישורים