| CVE | CVE-2025-42611 |
|---|---|
| Severity | MEDIUM · CVSS 3.1 6.5 |
| Weakness | CWE-295 |
| Affected versions | <= 7.20.x |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2026-05-05 |
What is the CVE-2025-42611 vulnerability?
The vulnerability lies in the shared certificate validation logic, which uses the system certificate store shared by all services. This causes a scope confusion, allowing any certificate authority present in the system trust store to be accepted in any context, with some exceptions. Consequently, a partial or complete bypass of authentication is possible in CAPsMAN, OpenVPN, Dot1X, and potentially other services.
Which RouterOS versions are vulnerable?
The affected versions are all up to and including 7.20.x. The fixed version has not yet been announced.
Is my router at risk?
A router is exposed if it runs a vulnerable version of RouterOS and has active services that rely on certificate validation, such as OpenVPN, CAPsMAN, or Dot1X, reachable from untrusted networks. The specific list of affected services has not yet been announced.
Is the CVE-2025-42611 vulnerability actively exploited?
As of the date of this article, the vulnerability is not listed in the CISA KEV catalog, and ENISA does not report it as exploited. There is no evidence of active exploitation.
How to protect the router from CVE-2025-42611?
The primary measure is to update to a version of RouterOS that fixes the vulnerability as soon as it becomes available. Until the fix is available, you can reduce exposure by limiting access to the affected services (OpenVPN, CAPsMAN, Dot1X) to trusted networks only, or by disabling them if not necessary.
Which RouterOS commands are needed to mitigate CVE-2025-42611?
Update RouterOS
The only definitive fix is the update. First, save the configuration; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2025-42611?
CVE-2025-42611 has a CVSS v3.1 score of 6.5, classified as MEDIUM severity.
Which RouterOS services are affected by CVE-2025-42611?
The description indicates that the vulnerability can affect OpenVPN, CAPsMAN, and Dot1X (802.1X), as well as potentially other services that use the shared certificate validation logic.
Is CVE-2025-42611 present in the CISA KEV catalog?
No, CVE-2025-42611 is not present in the CISA KEV catalog as of the date of this article.
What is the CWE classification of CVE-2025-42611?
CVE-2025-42611 is classified as CWE-295, i.e., “Improper Certificate Validation”.



