CVE CVE-2025-6443
Severity not yet disclosed
Weakness CWE-284
Affected versions 7.15.3, 7.16.2
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2025-06-25
Discrepant sources affected_versions: CVE.org → ['7.15.3, 7.16.2'], NVD CPE → ['< 7.20']

What is the CVE-2025-6443 vulnerability?

CVE-2025-6443 is an improper access control vulnerability (CWE-284) that occurs during VXLAN traffic processing. The flaw lies in the failure to validate the remote IP address against configured values before allowing traffic into the internal network. A remote attacker can exploit this lack of validation to bypass access restrictions and reach internal resources without needing to authenticate.

Which RouterOS versions are vulnerable?

The versions confirmed vulnerable by CVE.org are 7.15.3 and 7.16.2. NVD CPE, however, indicates all versions prior to 7.20. There is therefore a discrepancy between sources: CVE.org lists two specific versions, while NVD CPE uses an open range. The exact fixed version has not yet been disclosed.

Is my router at risk?

A router is exposed if the VXLAN service is active and reachable from untrusted networks. Since authentication is not required to exploit the vulnerability, even a configuration that limits access to specific IPs could be bypassed if the remote IP validation is incorrect. If VXLAN is not used or the service is not reachable from external networks, the risk is reduced.

Is the CVE-2025-6443 vulnerability actively exploited?

As of the date of this article, CVE-2025-6443 is not listed in the CISA KEV catalog, and ENISA does not report it as exploited. There is no public evidence of active exploitation.

How to protect the router from CVE-2025-6443?

Update RouterOS to the fixed version as soon as it is available from the vendor, ensuring it is a stable release and not a beta or RC. While waiting for the update, consider disabling the VXLAN service if it is not strictly necessary, or limit its reachability from untrusted networks using firewall rules. Verify that VXLAN access configurations are consistent with the network security policies.

Which RouterOS commands are needed to mitigate CVE-2025-6443?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2025-6443 require authentication to be exploited?

No, CVE-2025-6443 does not require authentication: a remote attacker can exploit the vulnerability without valid credentials.

What is the CVSS score for CVE-2025-6443?

The CVSS score has not yet been disclosed in available sources.

Is CVE-2025-6443 present in the CISA KEV catalog?

No, CVE-2025-6443 is not present in the CISA KEV catalog as of the date of this article.

Which RouterOS versions fix CVE-2025-6443?

The exact fix version has not yet been announced. NVD CPE indicates that versions prior to 7.20 are vulnerable, but the stable release that definitively resolves the issue must be verified with the vendor.

Does disabling VXLAN eliminate the risk of CVE-2025-6443?

Yes, disabling the VXLAN service eliminates the specific exposure to CVE-2025-6443, as the vulnerability manifests exclusively during VXLAN traffic processing.

Official sources