Experts from Tenable Research have devised a new attack technique to fully compromise MikroTik Routers. The attack technique leverages a known directory traversal flaw tracked as CVE-2018-14847. The vulnerability was rated medium in severity was discovered in April, it affects the Winbox, that is a management console for RouterOS software. The most critical of these vulnerabilities is the authenticated RCE, which would allow attackers to potentially gain full system access. Only approximately 30 percent of vulnerable modems have been patched, this means that roughly 200,000 routers could be hacked.”]
Source: https://securityaffairs.co/wordpress/76940/hacking/mikrotik-routers-attack-poc.html