NewsSecurity Vulnerabilities

Mikrotik RouterOS VXLAN Source IP Improper Access Control Vulnerability (CVE-2025-6443)

CVE number = CVE-2025-6443

This vulnerability allows remote attackers to bypass access restrictions on affected installations of Mikrotik RouterOS.

Authentication is not required to exploit this vulnerability.

The specific flaw exists within the handling of remote IP addresses when processing VXLAN traffic.

The issue results from the lack of validation of the remote IP address against configured values prior to allowing ingress traffic into the internal network.

An attacker can leverage this vulnerability to gain access to internal network resources.

This issue has been fixed in RouterOS v7.20

Jason Davies

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.