| CVE | CVE-2025-10948 |
|---|---|
| Severity | HIGH · CVSS 3.1 8.8 · CVSS 4.0 7.4 |
| Weakness | CWE-119, CWE-120 |
| Affected versions | 7 |
| Fixed version | 7.20.1, 7.21beta2 |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2025-09-25 |
What is the CVE-2025-10948 vulnerability?
This is a buffer overflow in the parse_json_element function of the /rest/ip/address/print file, within the libjson.so component. Manipulation of input data leads to a buffer overflow. The attack can be executed remotely. Exploit code has been made public and may be used.
Which RouterOS versions are vulnerable?
The affected versions are those in the 7 series. The indicated fixed versions are 7.20.1 and 7.21beta2. Since 7.21beta2 is a development version, the stable/long-term releases listed among the affected versions remain vulnerable: an administrator must not install a beta in production without being aware of this.
Is my router at risk?
A router is exposed if it runs RouterOS 7 and the REST endpoint /rest/ip/address/print is reachable from untrusted networks. The vulnerability concerns the libjson.so component and the parse_json_element function, so any traffic reaching this endpoint via the REST service can potentially trigger the buffer overflow.
Is the CVE-2025-10948 vulnerability actively exploited?
As of the date of the article, it is not reported as exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as exploited. However, exploit code has been made public and may be used.
How to protect the router from CVE-2025-10948?
Update RouterOS to version 7.20.1 or higher. If you are using a beta version such as 7.21beta2, verify that it is suitable for your production environment. Alternatively, restrict access to the REST endpoint /rest/ip/address/print from untrusted networks, for example through firewall rules or network restrictions, to reduce the attack surface.
Which RouterOS commands are needed to mitigate CVE-2025-10948?
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2025-10948 require authentication to be exploited?
Yes, the CVSS 3.1 vector indicates PR:L (Privileges Required: Low), so the attacker requires low privileges to exploit the vulnerability.
What is the CVSS score for CVE-2025-10948?
The CVSS 3.1 score is 8.8 (HIGH) and the CVSS 4.0 score is 7.4 (HIGH), both assigned by cna@vuldb.com.
What is the fixed version for CVE-2025-10948?
The fixed versions are 7.20.1 and 7.21beta2. Since 7.21beta2 is a development version, it is recommended to use 7.20.1 in production environments.
Is CVE-2025-10948 present in the CISA KEV catalog?
No, as of the date of the article, CVE-2025-10948 is not present in the CISA KEV catalog.
Official sources
- https://github.com/a2ure123/libjson-unicode-buffer-overflow-poc
- https://github.com/a2ure123/libjson-unicode-buffer-overflow-poc#technical-proof-of-concept
- https://vuldb.com/?ctiid.325818
- https://vuldb.com/?id.325818
- https://vuldb.com/?submit.652387
- https://github.com/a2ure123/libjson-unicode-buffer-overflow-poc



