| CVE | CVE-2021-27221 |
|---|---|
| Severity | HIGH · CVSS 3.1 8.1 |
| Weakness | not yet disclosed |
| Affected versions | not yet disclosed |
| Fixed version | not yet disclosed |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2021-03-19 |
What is the CVE-2021-27221 vulnerability?
The vulnerability allows a remote authenticated user with FTP access to create or overwrite arbitrary .rsc files using the /export command. The vendor’s position is that this is intended behavior due to how user policies work in RouterOS 6.47.9.
Which RouterOS versions are vulnerable?
The version specified as vulnerable is RouterOS 6.47.9. Fixed versions have not yet been disclosed.
Is my router at risk?
A router is exposed if the cleartext FTP service is active and reachable from untrusted networks, and if there are users with policies that allow FTP access. Since FTP is a legacy cleartext service, it should not be active on any modern router.
Is the CVE-2021-27221 vulnerability actively exploited?
As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA.
How to protect the router from CVE-2021-27221?
The primary mitigation is to completely disable the cleartext FTP service, as it is an insecure legacy protocol. Alternatively, if FTP must remain active for operational needs, you must ensure that only trusted users with strictly limited policies can access it, avoiding granting FTP policies to unprivileged users.
Which RouterOS commands are needed to mitigate CVE-2021-27221?
Temporary mitigation: legacy service
The flaw concerns cleartext services (Telnet, FTP) that should not be active on any modern router.
/ip service set telnet disabled=yes
/ip service set ftp disabled=yes
Update RouterOS
The only definitive fix is an update. Save the configuration first; the installation reboots the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2021-27221 require authentication?
Yes, CVE-2021-27221 requires the attacker to be a remote authenticated user with FTP access.
What is the CVSS score for CVE-2021-27221?
The CVSS v3.1 score assigned by NVD is 8.1, with HIGH severity.
Is disabling FTP enough to mitigate CVE-2021-27221?
Yes, disabling the cleartext FTP service eliminates the attack surface described in CVE-2021-27221.
Is CVE-2021-27221 in the CISA KEV catalog?
No, CVE-2021-27221 is not present in the CISA KEV catalog as of the date of the article.



