MikroTik Router OS Directory Traversal Vulnerability

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Published 6 Sep 2026Updated 6 Sep 2026576 sources
CVSS 0.0 ✓ VERIFIED REFERENCE△ CISA KEV

What happened

MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

Affected versions

RouterOS: See original advisory Fixed: See vendor advisory.

Why it matters

This source correlation may provide earlier visibility while structured CVE metadata is still being updated.

Detection & mitigation

  • Review the original advisory and validate affected versions.
  • Apply vendor-provided updates or mitigations when available.

Public PoC references

RepositoryAuthorFirst seenReference
Exploit-DB 45578MicroTik RouterOS < 6.43rc3 - Remote RootJacob Baines2018-10-10VerifiedPoC-in-GitHub · BasuCert/WinboxPoCProof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)★ 520BasuCert2018-06-24CandidatePoC-in-GitHub · msterusky/WinboxExploitC# implementation of BasuCert/WinboxPoC [Winbox Critical Vulnerability (CVE-2018-14847)]★ 7msterusky2018-09-11CandidatePoC-in-GitHub · syrex1013/MikroRootAutomated version of CVE-2018-14847 (MikroTik Exploit)★ 15syrex10132018-10-13CandidatePoC-in-GitHub · jas502n/CVE-2018-14847MikroTik RouterOS Winbox未经身份验证的任意文件读/写漏洞★ 30jas502n2018-12-15CandidatePoC-in-GitHub · mahmoodsabir/mikrotik-beastMass MikroTik WinBox Exploitation tool, CVE-2018-14847★ 6mahmoodsabir2019-05-26CandidatePoC-in-GitHub · Tr33-He11/winboxPOCProof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)★ 1Tr33-He112019-09-25CandidatePoC-in-GitHub · sinichi449/Python-MikrotikLoginExploitPoC of CVE-2018-14847 Mikrotik Vulnerability using simple script★ 21sinichi4492019-09-29CandidatePoC-in-GitHub · yukar1z0e/CVE-2018-14847★ 1yukar1z0e2020-04-29CandidatePoC-in-GitHub · hacker30468/Mikrotik-router-hackThis is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.★ 55hacker304682021-04-21CandidatePoC-in-GitHub · babyshen/routeros-CVE-2018-14847-bythewayBy the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:★ 4babyshen2022-10-31CandidatePoC-in-GitHub · K3ysTr0K3R/CVE-2018-14847-EXPLOITA PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read★ 6K3ysTr0K3R2024-04-22CandidatePoC-in-GitHub · tausifzaman/CVE-2018-14847This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.★ 1tausifzaman2025-04-16CandidatePoC-in-GitHub · TheMalwareGuardian/CVE-2018-14847Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the credential database.★ 0TheMalwareGuardian2026-04-27CandidatePoC-in-GitHub · mourafuseti/VULNERAVEL-CVE-2018-14847---CREDENCIAIS-EXTRAIDASVULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON★ 1mourafuseti2026-05-20CandidatePoC-in-GitHub · luel-4013/misfortune-cookieThis interactive suite targets CVE-2014-9222 (Misfortune Cookie) in legacy RomPager web servers, alongside modular testing for CVE-2017-17215 (Huawei HG532 RCE), CVE-2018-14847 (MikroTik WinBox credential leak), and the CVE-2021-27101 / CVE-2021-27102 exploit chain (Accellion FTA).★ 0luel-40132026-09-07Candidate