{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3omikrotikrouteros/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2018-14847"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RouterOS (\u003c 6.42.1)","Winbox"],"_cs_severities":["high"],"_cs_tags":["vulnerability","credential-access","network-infrastructure"],"_cs_type":"advisory","_cs_vendors":["MikroTik"],"content_html":"\u003cp\u003eCVE-2018-14847 is a critical vulnerability affecting the Winbox service in MikroTik RouterOS, enabling unauthenticated attackers to perform arbitrary file reads. The vulnerability resides in how the service handles file requests, specifically allowing unauthorized access to the 'user.dat' file, which contains device account credentials. The passwords stored within this file are protected by a weak XOR-based obfuscation using a static key derived from a hardcoded salt. Publicly available exploit scripts automate the entire attack chain, from establishing the Winbox session to extracting and decrypting credentials. This vulnerability impacts MikroTik RouterOS versions up to 6.42. Defenders should prioritize patching, as the presence of functional exploit code significantly lowers the barrier for attackers to gain full administrative control over exposed routing infrastructure.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker performs network scanning to identify reachable Winbox services on TCP port 8291.\u003c/li\u003e\n\u003cli\u003eThe attacker establishes an initial session with the Winbox service by sending a crafted 'FIRST_PAYLOAD'.\u003c/li\u003e\n\u003cli\u003eThe service responds, and the attacker extracts the session ID from the 38th byte of the response.\u003c/li\u003e\n\u003cli\u003eThe attacker injects the extracted session ID into a 'SECOND_PAYLOAD' at the 19th byte position.\u003c/li\u003e\n\u003cli\u003eThe attacker sends this second payload to request the sensitive file '/flash/rw/store/user.dat'.\u003c/li\u003e\n\u003cli\u003eThe service returns the file content to the attacker, including encrypted user credentials.\u003c/li\u003e\n\u003cli\u003eThe attacker parses the data for 'M2' entries and applies XOR decryption using the MD5 hash of the username concatenated with a hardcoded salt.\u003c/li\u003e\n\u003cli\u003eThe attacker obtains plain-text administrative credentials and gains full access to the router.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate exposure of all local administrative credentials stored on the router. Given the high-privilege nature of these accounts, attackers can gain complete control of the network device, leading to traffic interception, modification of network configuration, deployment of backdoors, or the utilization of the compromised router as an entry point for further lateral movement within the organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all internet-facing or internal MikroTik RouterOS devices to the current long-term or stable release versions, specifically ensuring the system is at or above version 6.42.1 (for stable) or 6.40.8 (for long-term). Block external access to TCP port 8291 via perimeter firewalls if Winbox management is not strictly required from remote locations. Use the Sigma rule below to monitor for mass scanning or exploitation attempts targeting the Winbox service.\u003c/p\u003e\n","date_modified":"2026-08-29T18:47:14Z","date_published":"2026-08-29T18:47:14Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2018-14847/","summary":"An unauthenticated remote file read vulnerability in MikroTik RouterOS (CVE-2018-14847) allows attackers to extract and decrypt administrative credentials, leading to full system compromise.","title":"Exploitation of CVE-2018-14847 in MikroTik RouterOS","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2018-14847/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}