Loading
The container package in MikroTik RouterOS 7.4beta4 allows an attacker to create mount points pointing to symbolic links, which resolve to locations on the host device. This allows the attacker to mount any arbitrary file to any location on the host.
Use CWE-59, Mikrotik vendor hub and Routeros product page to widen CVE-2022-34960 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2017-20149, CVE-2023-30799 and CVE-2022-45313 for nearby disclosures in the same product family.