MikroTik RouterOS IPv6 UDP Traceroute Firewall Bypass Vulnerability

Vulnerability

A vulnerability has been identified in MikroTik RouterOS 7, prior to 7.14, allowing a firewall bypass for incoming IPv6 UDP traceroute packets. The default firewall configuration in RouterOS 7 accepted UDP packets in the traceroute port range, which an attacker could exploit by crafting packets to manipulate the acceptance of these packets. This exposure could lead to unauthorized access to UDP services such as CAPsMAN, DNS, and containers, where enabled.

Impact

Exploitation of this vulnerability could bypass the default IPv6 firewall, allowing unauthorized access to exposed UDP services.

Reproduction

The vulnerability can be reproduced by sending crafted IPv6 UDP packets within the traceroute port range of 33434 to 33534. These packets will be accepted by the default firewall rules, bypassing any intended protections.

Remediation

Users are advised to update to MikroTik RouterOS version 7.14 or later, and to adjust their firewall scripts to specify the destination port range of 33434 to 33534.

Added: Jun 30, 2025, 5:57 PM
Updated: Jun 30, 2025, 5:57 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
2.5
exploitability
8.1
remediation
7.7
relevance
0.2
threat
1.6
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.