MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published: 2019-04-10T20:01:00

Updated: 2024-08-04T19:26:27.694Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3943

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-04-10T21:29:01.823

Modified: 2019-12-17T19:19:10.487

Link: CVE-2019-3943

cve-icon Redhat

No data.