Improper Access Control in Mikrotik RouterOS Affecting Remote IP Handling
CVE-2025-6443

7.2HIGH

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
25 June 2025

What is CVE-2025-6443?

The vulnerability in Mikrotik RouterOS relates to the mishandling of remote IP addresses when processing VXLAN traffic. This flaw results from insufficient validation of remote IP addresses, allowing unauthorized ingress traffic into internal networks. Malicious actors can exploit this weakness to bypass access restrictions and potentially gain access to sensitive internal resources without the need for authentication.

Affected Version(s)

RouterOS 7.15.3, 7.16.2

References

CVSS V3.0

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-6443 : Improper Access Control in Mikrotik RouterOS Affecting Remote IP Handling