CVE-2018-14847
MikroTik Router OS Directory Traversal Vulnerability
- Published
- Aug 2, 2018
- Updated
- Oct 21, 2025
- Assigning CNA
- mitre
- Evidence observed
- Oct 10, 2018
MikroTik Router OS Directory Traversal Vulnerability
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
By the Way is an exploit that enables a root shell on Mikrotik devices running RouterOS versions:
Proof-of-concept exploit for CVE-2018-14847 (MikroTik WinBox vulnerability) enabling arbitrary file read and plaintext password extraction via TCP/IP or Layer 2 MAC server.
Proof-of-concept exploit for CVE-2018-14847 allowing arbitrary file read of plaintext passwords from MikroTik RouterOS WinBox service, with TCP/IP and Layer 2 MAC server support.
A PoC exploit for CVE-2018-14847 - MikroTik WinBox File Read
VULNERAVEL CVE-2018-14847 - CREDENCIAIS EXTRAIDAS MIKROTIK EM PYTHON
PoC of CVE-2018-14847 Mikrotik Vulnerability using simple script
Automated version of CVE-2018-14847 (MikroTik Exploit)
This is a proof of concept of the critical WinBox vulnerability (CVE-2018-14847) which allows for arbitrary file read of plain text passwords. The vulnerability has long since been fixed, so this project has ended and will not be supported or updated anymore. You can fork it and update it yourself instead.
Analysis and PoC for CVE-2018-14847, MikroTik RouterOS Winbox information disclosure vulnerability allowing unauthenticated read access to the credential database.
Proof of Concept of Winbox Critical Vulnerability (CVE-2018-14847)
Exploit for CVE-2018-14847 targeting MikroTik RouterOS to create a global proxy and extract credentials via PPTP server setup.
Interactive PoC suite for CVE-2014-9222 (Misfortune Cookie) and related router exploits, featuring detection, auth bypass, DoS, and RCE modules with a scan mode for multiple vulnerabilities.
Mass MikroTik WinBox Exploitation tool, CVE-2018-14847
Jacob Baines · hardware · Oct 10, 2018
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.