Vulnerability Description
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mikrotik | Routeros | 6.47.9 |
References
- https://onovy.medium.com/routeros-user-with-just-ftp-policy-can-write-to-filesysExploitThird Party Advisory
- https://onovy.medium.com/routeros-user-with-just-ftp-policy-can-write-to-filesysExploitThird Party Advisory
FAQ
What is CVE-2021-27221?
CVE-2021-27221 is a vulnerability with a CVSS score of 8.1 (HIGH). MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior becaus...
How severe is CVE-2021-27221?
CVE-2021-27221 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-27221?
Check the references section above for vendor advisories and patch information. Affected products include: Mikrotik Routeros.