| CVE | CVE-2025-6563 |
|---|---|
| Severity | MEDIUM · CVSS 4.0 4.8 |
| Weakness | CWE-20 |
| Affected versions | < 7.19.2 |
| First non-vulnerable version | 7.19.2 (per branch) |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2025-07-03 |
What is the CVE-2025-6563 vulnerability?
CVE-2025-6563 is a cross-site scripting (XSS) vulnerability that allows an attacker to inject the javascript protocol into the dst parameter of the hotspot service. When the victim accesses the malicious URL and authenticates, the script is executed. Additionally, the login POST request can be converted into a GET request, allowing the attacker to send a specific URL that automatically authenticates the victim into the attacker’s account and triggers the payload.
Which RouterOS versions are vulnerable?
RouterOS versions lower than 7.19.2 are vulnerable to CVE-2025-6563. The exact fixed version is not specified beyond the lower bound “7.19.2”, but upgrading to that version or higher eliminates the vulnerability.
Is my router at risk?
A router is at risk if the hotspot service is active and reachable from untrusted networks. The vulnerability requires a user to interact with a malicious URL and authenticate through the hotspot interface, so exposure depends on public or semi-public access to the hotspot login portal.
Is the CVE-2025-6563 vulnerability actively exploited?
As of the date of the article, CVE-2025-6563 is not listed in the CISA KEV catalog nor reported as exploited by ENISA. There is no evidence of active exploitation in real-world environments.
How to protect the router from CVE-2025-6563?
The primary action is to update RouterOS to a version equal to or higher than 7.19.2. Alternatively, if an immediate update is not possible, you can reduce exposure by limiting access to the hotspot service to trusted networks only or temporarily disabling it if not in use.
Which RouterOS commands are needed to mitigate CVE-2025-6563?
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score of CVE-2025-6563?
CVE-2025-6563 has a CVSS v4.0 score of 4.8, classified as MEDIUM severity.
Does exploiting CVE-2025-6563 require authentication?
No, CVE-2025-6563 does not require preliminary privileges (PR:N), but it requires user interaction (UI:A) to access the malicious URL and complete the hotspot login.
Is disabling the hotspot service enough to mitigate CVE-2025-6563?
Yes, disabling the hotspot service eliminates the attack surface for CVE-2025-6563, as the vulnerability is specific to that component.
Is CVE-2025-6563 in the CISA KEV catalog?
No, CVE-2025-6563 is not present in the CISA KEV catalog as of the date of the article.



