Vulnerability Details CVE-2021-27221
MikroTik RouterOS 6.47.9 allows remote authenticated ftp users to create or overwrite arbitrary .rsc files via the /export command. NOTE: the vendor's position is that this is intended behavior because of how user policies work
Exploit prediction scoring system (EPSS) score
EPSS Score 0.419
EPSS Ranking 97.3%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 8.5
Products affected by CVE-2021-27221
-
cpe:2.3:o:mikrotik:routeros:6.47.9