CVE-2025-42611
Severity CVSS v4.0:
Pending analysis
Type:
CWE-295
Improper Certificate Validation
Publication date:
05/05/2026
Last modified:
05/05/2026
Description
RouterOS provides various services that rely on correct<br />
verification of client and server certificates to secure confidentiality and<br />
integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X),<br />
among others.<br />
<br />
<br />
<br />
The vulnerability lies in shared certificate validation<br />
logic which uses the system certificate store that is shared and equally<br />
trusted by all system services. This causes confusion of scope, allowing any<br />
certificate authority present in the system-wide trust store to be trusted in<br />
any context (with some exceptions), allowing partial or full authentication<br />
bypass in CAPsMAN, OpenVPN, Dot1X and potentially others.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM



