CVE-2021-27221

MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
Configurations

Configuration 1 (hide)

cpe:2.3:o:mikrotik:routeros:6.47.9:*:*:*:-:*:*:*

History

21 Nov 2024, 05:57

Type Values Removed Values Added
References () https://onovy.medium.com/routeros-user-with-just-ftp-policy-can-write-to-filesystem-cve-2021-27221-e3e45d780dfe - Exploit, Third Party Advisory () https://onovy.medium.com/routeros-user-with-just-ftp-policy-can-write-to-filesystem-cve-2021-27221-e3e45d780dfe - Exploit, Third Party Advisory

07 Nov 2023, 03:31

Type Values Removed Values Added
Summary ** DISPUTED ** MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work. MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work

Information

Published : 2021-03-19 03:15

Updated : 2024-11-21 05:57


NVD link : CVE-2021-27221

Mitre link : CVE-2021-27221

CVE.ORG link : CVE-2021-27221


JSON object : View

Products Affected

mikrotik

  • routeros