MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.tenable.com/security/research/tra-2019-16 |
![]() ![]() |
History
Tue, 15 Jul 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
epss
|
epss
|

Status: PUBLISHED
Assigner: tenable
Published: 2019-04-10T20:01:00
Updated: 2024-08-04T19:26:27.694Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3943

No data.

Status : Modified
Published: 2019-04-10T21:29:01.823
Modified: 2024-11-21T04:42:54.907
Link: CVE-2019-3943

No data.