CVE-2025-42611
RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others.
The vulnerability lies in shared certificate validation logic which uses the system certificate store that is shared and equally trusted by all system services. This causes confusion of scope, allowing any certificate authority present in the system-wide trust store to be trusted in any context (with some exceptions), allowing partial or full authentication bypass in CAPsMAN, OpenVPN, Dot1X and potentially others.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
- Base score: 6.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.19%
- Percentile among all scored CVEs: 7
- Score date: 9/30/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (3)
⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.
CWEs
- CWE-295
References
Raw JSON (NVD)
Show
{
"id": "CVE-2025-42611",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-42611",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-05-05T12:38:09.152163Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.5,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"affectedData": [
{
"vendor": "Mikrotik",
"product": "RouterOS",
"versions": [
{
"status": "affected",
"version": "0",
"versionType": "semver",
"lessThanOrEqual": "7.20.x"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-05-05T11:16:31.827",
"references": [
{
"url": "https://www.cert.si/en/cve-2025-42611/",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}
],
"vulnStatus": "Awaiting Analysis",
"weaknesses": [
{
"type": "Secondary",
"source": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
"description": [
{
"lang": "en",
"value": "CWE-295"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "RouterOS provides various services that rely on correct\nverification of client and server certificates to secure confidentiality and\nintegrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X),\namong others.\n\n\n\nThe vulnerability lies in shared certificate validation\nlogic which uses the system certificate store that is shared and equally\ntrusted by all system services. This causes confusion of scope, allowing any\ncertificate authority present in the system-wide trust store to be trusted in\nany context (with some exceptions), allowing partial or full authentication\nbypass in CAPsMAN, OpenVPN, Dot1X and potentially others."
},
{
"lang": "es",
"value": "RouterOS proporciona varios servicios que dependen de la verificación correcta de certificados de cliente y servidor para asegurar la confidencialidad y la integridad de las comunicaciones. Esto incluye OpenVPN, CAPsMAN, Dot1x (802.1X), entre otros.\n\nLa vulnerabilidad reside en la lógica compartida de validación de certificados que utiliza el almacén de certificados del sistema que es compartido y igualmente confiado por todos los servicios del sistema. Esto causa confusión de alcance, permitiendo que cualquier autoridad de certificación presente en el almacén de confianza de todo el sistema sea confiada en cualquier contexto (con algunas excepciones), permitiendo un bypass de autenticación parcial o total en CAPsMAN, OpenVPN, Dot1X y potencialmente otros."
}
],
"lastModified": "2026-09-30T22:10:00.273",
"sourceIdentifier": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158"
}