MikroTik Router OS Directory Traversal Vulnerability
MikroTik · RouterOS
Date added (CISA)
2021-12-01
Remediation due
2022-06-01
Known ransomware use
Not indicated
Remediation priority
P2 — past CISA due date
Description
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.