PT-2018-1757 · Mikrotik · Routeros+2

Jacob Baines

·

Published

2018-04-23

·

Updated

2026-03-10

·

CVE-2018-14847

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS versions prior to 6.42
Description The issue is caused by a directory traversal vulnerability in the WinBox interface of MikroTik RouterOS, allowing unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files. This vulnerability has been exploited by various malware, including TrickBot, to compromise routers and use them as proxies for command and control (C2) communication. More than 200,000 MikroTik routers worldwide are controlled by attackers, and these compromised devices are used for various malicious activities, including DDoS attacks and cryptojacking.
Recommendations To secure their routers, users are advised to update their devices with the latest security patches, set strong passwords, and disable external access to the administration interface. As a temporary workaround, consider disabling the WinBox interface until a patch is available. Restrict access to the administration interface to minimize the risk of exploitation. Avoid using default passwords and ensure that all passwords are strong and unique. Keep the RouterOS software up to date with the latest security patches.

Exploit

Fix

Improper Authentication

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2018-01357
CVE-2018-14847

Affected Products

Mikrotik Routeros
Routeros
Winbox