#VU22424 Path traversal in MikroTik RouterOS - CVE-2019-3976
Published: October 30, 2019
MikroTik RouterOS
MikroTik
Description
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences in the filenames of the packages. A remote attacker can trick the victim into installing an updated with a specially crafted name and enable developer shell.