Impact
MikroTik RouterOS before 7.24.2 contains a path traversal flaw in the container package OCI/tar image extraction that allows attackers to write, delete, or hard‑link files outside the container root. By supplying a crafted image containing symlinks that point to arbitrary paths, the unsanitized tar extraction during the /container/add operation can create or remove files on the persistent data partition while running with root privileges, without ever launching the container. This vulnerability can also delete files through overlayfs whiteout and create hard links, giving an attacker powerful control over the device’s filesystem. The flaw affects all RouterOS builds that include the unpatched container binaries, including the 7.23.x long‑term branch where container‑7.23.3.npk and container‑7.23.4.npk remain vulnerable.
Affected Systems
All MikroTik RouterOS firmware builds before 7.24.2 are affected, including the 7.23.x long‑term branch. The container binaries in container-7.23.3.npk and container-7.23.4.npk are byte‑identical and remain vulnerable, and there is no patched long‑term release available at the time of the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 6.9, indicating moderate severity. EPSS score is <1%, and it is not listed in the CISA KEV catalog. The path traversal flaw is triggered when a container image is imported via the /container/add API, and it allows an attacker who can upload a crafted image to write files, delete files, or create hard links on the RouterOS persistent data partition. These capabilities can compromise the device’s filesystem integrity and availability, potentially disabling critical system functions if the device is not properly protected from unauthorized container uploads. The risk is higher if the /container/add API is exposed without adequate access controls.
OpenCVE Enrichment