| CVE | CVE-2025-61481 |
|---|---|
| Severity | CRITICAL · CVSS 3.1 10.0 |
| Weakness | CWE-1188, CWE-200, CWE-319 |
| Affected versions | not yet announced |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2025-10-27 |
What is the CVE-2025-61481 vulnerability?
CVE-2025-61481 is a flaw that exposes the WebFig management interface over plain HTTP by default. This configuration allows an on-path attacker to execute injected JavaScript in the administrator’s browser and intercept login credentials. The issue is classified as critical with a CVSS v3.1 score of 10.0, indicating high impact on confidentiality and integrity and low impact on availability.
Which RouterOS versions are vulnerable?
The affected versions are RouterOS v.7.14.2 and SwOS v.2.18. The fixed version has not yet been announced.
Is my router at risk?
A router is exposed if the WebFig service is active and reachable from untrusted networks. If the web management interface is accessible from the Internet or from uncontrolled network segments, an on-path attacker can exploit the cleartext transmission to intercept credentials. If you do not use WebFig, you eliminate the risk by disabling the service.
Is the CVE-2025-61481 vulnerability actively exploited?
As of the date of this article, there is no evidence that the vulnerability is being actively exploited. It is not present in the CISA KEV catalog, and ENISA does not report it as exploited.
How to protect your router from CVE-2025-61481?
The primary mitigation is to disable the WebFig service if it is not strictly necessary. If the web interface is required, it must be configured to be reachable exclusively from the trusted administration network, preventing access from untrusted networks. Updating to a fixed version, when available, is the definitive solution.
Which RouterOS commands are needed to mitigate CVE-2025-61481?
Temporary mitigation: www service
The flaw concerns the web management service (WebFig). If you do not use it, disable it; if you do use it, it must be reachable only from the administration network.
# quali servizi di gestione sono attivi e da dove sono raggiungibili
/ip service print
# se WebFig non serve: spegnilo
/ip service set www disabled=yes
/ip service set www-ssl disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set www address=192.168.88.0/24
/ip service set www-ssl address=192.168.88.0/24
Update RouterOS
The only definitive fix is an update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2025-61481?
CVE-2025-61481 has a CVSS v3.1 score of 10.0, classified as critical. The CVSS vector indicates a network attack with low complexity, no authentication required, and no user interaction required.
Is CVE-2025-61481 present in the CISA KEV catalog?
CVE-2025-61481 is not present in the CISA KEV catalog. As of the date of this article, the vulnerability is not reported as actively exploited.
Which services are involved in CVE-2025-61481?
CVE-2025-61481 concerns the WebFig management web service. The flaw exposes the interface via cleartext HTTP, making routers vulnerable if this service is left active and reachable from untrusted networks.
What are the associated weaknesses (CWE) for CVE-2025-61481?
CVE-2025-61481 is associated with the weaknesses CWE-1188 (Initialization of a Resource with an Insecure Default), CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-319 (Cleartext Transmission of Sensitive Information).



