| CVE | CVE-2023-47310 |
|---|---|
| Severity | MEDIUM · CVSS 3.1 6.5 |
| Weakness | CWE-1174 |
| Affected versions | not yet announced |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2025-06-30 |
What is the CVE-2023-47310 vulnerability?
The vulnerability is a misconfiguration in the default settings of MikroTik RouterOS 7 that allows incoming IPv6 UDP traceroute packets. The issue was fixed in version 7.14.
Which RouterOS versions are vulnerable?
The vulnerable versions are those of RouterOS 7 prior to 7.14. The fixed version is 7.14.
Is my router at risk?
A router is exposed if it runs a version of RouterOS 7 prior to 7.14 and receives IPv6 UDP traceroute traffic from untrusted networks. The vulnerability concerns the default firewall settings for this type of traffic.
Is the CVE-2023-47310 vulnerability actively exploited?
As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA.
How to protect the router from CVE-2023-47310?
Update the router to version 7.14 or later of RouterOS. Alternatively, you can manually configure firewall rules to block incoming IPv6 UDP traceroute packets.
Which RouterOS commands are needed to mitigate CVE-2023-47310?
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2023-47310?
The CVSS v3.1 score for CVE-2023-47310 is 6.5, with MEDIUM severity.
Which RouterOS version fixes CVE-2023-47310?
The RouterOS version that fixes CVE-2023-47310 is 7.14.
Does CVE-2023-47310 require authentication to be exploited?
No, CVE-2023-47310 does not require authentication, as indicated by the CVSS vector (PR:N).



