Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-6443

Опубликовано: 25 июн. 2025
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of remote IP addresses when processing VXLAN traffic. The issue results from the lack of validation of the remote IP address against configured values prior to allowing ingress traffic into the internal network. An attacker can leverage this vulnerability to gain access to internal network resources. Was ZDI-CAN-26415.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*
Версия до 7.20 (исключая)

EPSS

Процентиль: 43%
0.00209
Низкий

7.2 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 7.2
github
8 месяцев назад

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability. This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of remote IP addresses when processing VXLAN traffic. The issue results from the lack of validation of the remote IP address against configured values prior to allowing ingress traffic into the internal network. An attacker can leverage this vulnerability to gain access to internal network resources. Was ZDI-CAN-26415.

CVSS3: 7.2
fstec
12 месяцев назад

Уязвимость реализации прикладного программного интерфейса операционной системы RouterOS маршрутизаторов MikroTik, позволяющая нарушителю получить доступ к ресурсам внутренней сети

EPSS

Процентиль: 43%
0.00209
Низкий

7.2 High

CVSS3

Дефекты

CWE-284