CVE CVE-2018-14847
Severity CRITICAL · CVSS 3.1 9.1
Weakness CWE-22
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited YES — CISA KEV catalog since 2021-12-01
CISA Advisory none
Published 2018-08-02

What is the CVE-2018-14847 vulnerability?

CVE-2018-14847 is a Path Traversal vulnerability in the MikroTik RouterOS WinBox interface. The flaw allows an unauthenticated remote attacker to read arbitrary files from the system and an authenticated remote attacker to write arbitrary files. The associated CWE classification is “Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)”.

Which RouterOS versions are vulnerable?

The vulnerable RouterOS versions are all those up to and including 6.42. The exact fixed version is not specified in the available data, but you must upgrade to a version later than 6.42 to resolve the issue.

Is my router at risk?

A router is at risk if it runs a vulnerable RouterOS version (up to and including 6.42) and the WinBox service is active and reachable from untrusted networks. The vulnerability affects both IP-based and MAC-based access, so you must restrict both connection methods to the management network to reduce exposure.

Is the CVE-2018-14847 vulnerability actively exploited?

Yes, CVE-2018-14847 is included in the CISA KEV (Known Exploited Vulnerabilities) catalog since 2021-12-01. This means the vulnerability has been actively exploited in real-world attacks and requires applying updates according to the vendor’s instructions.

How to protect the router from CVE-2018-14847?

The primary protection is to update the RouterOS firmware to a version later than 6.42, which fixes the vulnerability. Additionally, it is essential to restrict access to the WinBox service to the management network only, disabling or filtering connections from untrusted networks via both IP and MAC.

Which RouterOS commands are needed to mitigate CVE-2018-14847?

Temporary mitigation: winbox service

The flaw affects WinBox, both via IP and via MAC address. You must restrict both access methods to the management network.

/ip service print
# Winbox via IP solo dalla rete di gestione (sostituisci con la tua)
/ip service set winbox address=192.168.88.0/24
# Winbox via MAC: spegnilo, o limitalo a un'interface-list di gestione
/tool mac-server mac-winbox set allowed-interface-list=none

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2018-14847?

The CVSS v3.1 score assigned to CVE-2018-14847 is 9.1, with a severity classified as CRITICAL. The attack vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating a high risk to system confidentiality and integrity.

Does CVE-2018-14847 require authentication to be exploited?

No, CVE-2018-14847 allows an unauthenticated attacker to read arbitrary files. Writing arbitrary files, however, requires the attacker to be authenticated on the system.

On what date was CVE-2018-14847 added to the KEV catalog?

CVE-2018-14847 was added to the CISA KEV catalog on 2021-12-01, confirming that the vulnerability is subject to active exploitation.

Which RouterOS services are involved in CVE-2018-14847?

The service involved in CVE-2018-14847 is WinBox, both when accessible via IP address and when accessible via MAC address. Both access methods must be restricted to the management network to mitigate the risk.

Official sources