Default Settings Misconfiguration in MikroTik RouterOS 7 Exposing IPv6 UDP Traffic
CVE-2023-47310

6.5MEDIUM

Key Information:

Vendor

MikroTik

Status
Vendor
CVE Published:
30 June 2025

What is CVE-2023-47310?

A misconfiguration in the default settings of MikroTik RouterOS 7 allows incoming IPv6 UDP traceroute packets, potentially leading to unauthorized network exposure. This vulnerability, fixed in version 7.14, highlights the importance of securing default configurations to prevent unintended access and protect network integrity. Administrators are advised to review their configurations and update to the latest version to mitigate this risk.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.