{"api_version":"1","generated_at":"2026-07-24T20:41:21+00:00","cve":"CVE-2019-15055","urls":{"html":"https://cve.report/CVE-2019-15055","api":"https://cve.report/api/cve/CVE-2019-15055.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-15055","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-15055"},"summary":{"title":"CVE-2019-15055","description":"MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2019-08-26 21:15:00","updated_at":"2020-10-06 12:15:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://fortiguard.com/zeroday/FG-VD-19-108","name":"https://fortiguard.com/zeroday/FG-VD-19-108","refsource":"MISC","tags":["Third Party Advisory"],"title":"Fortinet Discovers MikroTik RouterOS Authenticated Arbitrary File Deletion Vulnerability | FortiGuard","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90","name":"https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90","refsource":"MISC","tags":["Press/Media Coverage","Third Party Advisory"],"title":"Rooting RouterOS with a USB Drive - Tenable TechBlog - Medium","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055","name":"https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"routeros/poc/cve_2019_15055 at master · tenable/routeros · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://mikrotik.com/download/changelogs/testing-release-tree","name":"https://mikrotik.com/download/changelogs/testing-release-tree","refsource":"CONFIRM","tags":["Release Notes","Vendor Advisory"],"title":"MikroTik Routers and Wireless - Software","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://forum.mikrotik.com/viewtopic.php?t=151603","name":"https://forum.mikrotik.com/viewtopic.php?t=151603","refsource":"CONFIRM","tags":[],"title":"v6.45.5 [stable] is released! - MikroTik","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-15055","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15055","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"15055","vulnerable":"1","versionEndIncluding":"6.44.5","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"mikrotik","cpe5":"routeros","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"15055","vulnerable":"1","versionEndIncluding":"6.45.3","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"mikrotik","cpe5":"routeros","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2019-15055","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://mikrotik.com/download/changelogs/testing-release-tree","url":"https://mikrotik.com/download/changelogs/testing-release-tree"},{"refsource":"MISC","name":"https://fortiguard.com/zeroday/FG-VD-19-108","url":"https://fortiguard.com/zeroday/FG-VD-19-108"},{"refsource":"MISC","name":"https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90","url":"https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90"},{"refsource":"MISC","name":"https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055","url":"https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055"},{"refsource":"CONFIRM","name":"https://forum.mikrotik.com/viewtopic.php?t=151603","url":"https://forum.mikrotik.com/viewtopic.php?t=151603"}]}},"nvd":{"publishedDate":"2019-08-26 21:15:00","lastModifiedDate":"2020-10-06 12:15:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*","versionEndIncluding":"6.44.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*","versionStartIncluding":"6.45","versionEndIncluding":"6.45.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"15055","Ordinal":"154351","Title":"CVE-2019-15055","CVE":"CVE-2019-15055","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"15055","Ordinal":"1","NoteData":"MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"15055","Ordinal":"2","NoteData":"2019-08-26","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"15055","Ordinal":"3","NoteData":"2020-10-06","Type":"Other","Title":"Modified"}]}}}