What happened
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Affected versions
RouterOS: n/a Fixed: See vendor advisory.
Why it matters
This source correlation may provide earlier visibility while structured CVE metadata is still being updated.
Detection & mitigation
- Review the original advisory and validate affected versions.
- Apply vendor-provided updates or mitigations when available.
Public PoC references
RepositoryAuthorFirst seenReference
github.comNVD reference2018-08-02Verifiedgithub.comNVD reference2018-08-02Verifiedgithub.comNVD reference2018-08-02Verifiedgithub.comNVD reference2018-08-02Verifiedgithub.comNVD reference2018-08-02Verifiedn0p.meNVD reference2018-08-02Verifiedwww.exploit-db.comNVD reference2018-08-02VerifiedExploit-DB 45578MicroTik RouterOS < 6.43rc3 - Remote RootJacob Baines2018-10-10VerifiedSploitusStack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.luel-40132026-09-07T19:47:48Verifiedluel-4013/misfortune-cookieStack overflow in AllegroSoft RomPager cookie handling enables auth bypass, DoS, and RCE.luel-40132026-09-07T19:47:48VerifiedSource timeline
Discovered through CISA Known Exploited VulnerabilitiesView source ↗
CVE record published by NVDView source ↗
Added to CISA Known Exploited Vulnerabilities catalogView source ↗
Record history
Record created from the first normalized source observation.
Metadata and source references refreshed.