MBSD-SOC reported a renewed rise in attack traffic targeting MikroTik RouterOS devices vulnerable to CVE-2018-14847, a WinBox directory traversal flaw affecting versions 6.42 and earlier. The vulnerability allows unauthenticated attackers to read arbitrary files and authenticated attackers to write arbitrary files, and observed activity in August appeared aimed at retrieving the router user database through path traversal. MBSD-SOC said detections had previously spiked in April and May 2022, later declined, and then increased again from mid-August.
The campaign largely originated from Germany, which accounted for 99.7% of observed detections, while Japan represented 0.3%. Public exploit and proof-of-concept details for CVE-2018-14847 have long been available, increasing the risk to organizations still running unpatched RouterOS systems. Defenders were urged to update affected devices to the latest RouterOS release, while also noting the separate severe RouterOS issue CVE-2023-30799 disclosed later.

See which actors are running it and whether you're in range.
5 events from the most recent confirmed update back to the earliest known activity.
The CVE record for CVE-2018-14847 was updated and continued to reference multiple public exploit and proof-of-concept resources.
MBSD-SOC detected another increase in attacks targeting CVE-2018-14847 in mid-August 2023. The observed traffic appeared to attempt path traversal to retrieve the RouterOS user database, including requests for "/flash/rw/store/user.dat".
The MBSD-SOC article noted that a separate severe MikroTik RouterOS vulnerability, CVE-2023-30799, was reported in July 2023.
MBSD-SOC reported that attacks targeting MikroTik RouterOS vulnerability CVE-2018-14847 increased from April to May 2022 before later subsiding.
The CVE record for CVE-2018-14847 was published, documenting a directory traversal flaw in the WinBox interface of MikroTik RouterOS through version 6.42 that allows unauthenticated file reads and authenticated file writes.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.