CVE-2025-42611

Severity CVSS v4.0:
Pending analysis
Type:
CWE-295 Improper Certificate Validation
Publication date:
05/05/2026
Last modified:
05/05/2026

Description

RouterOS provides various services that rely on correct<br /> verification of client and server certificates to secure confidentiality and<br /> integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X),<br /> among others.<br /> <br /> <br /> <br /> The vulnerability lies in shared certificate validation<br /> logic which uses the system certificate store that is shared and equally<br /> trusted by all system services. This causes confusion of scope, allowing any<br /> certificate authority present in the system-wide trust store to be trusted in<br /> any context (with some exceptions), allowing partial or full authentication<br /> bypass in CAPsMAN, OpenVPN, Dot1X and potentially others.

References to Advisories, Solutions, and Tools