An issue has been published regarding how RouterOS services decide which certificate authorities (CAs) to trust. Several RouterOS services, such as OpenVPN, CAPsMAN and Dot1X (802.1X), use certificates to verify who they are talking to. In affected versions these services all use the same system-wide certificate store, so any CA certificate that is trusted on the router is trusted by every service. The issue has been assigned CVE-2025-42611 and was reported by SI-CERT.
What this means in practice: if your router has several CA certificates installed, for example one for OpenVPN and another for a CAPsMAN setup, a certificate issued by one CA could be accepted by a service that was only meant to trust the other one. Depending on your setup, this could allow a device or user to authenticate where it should not. An attacker still needs a certificate issued by one of the CAs already installed on your router, so a router with a single CA, or with no certificate-based services at all, is not at risk.
Who is affected: RouterOS versions before 7.21, on devices that use more than one CA certificate with certificate-verified services. RouterOS 6 is not affected.
Current status: RouterOS 7.21 introduced the ability to limit which CA each service trusts. This addresses the issue, but only if you configure it: after upgrading, review your OpenVPN, CAPsMAN and Dot1X settings and make sure each one is set to trust only the CA that is meant for it, instead of relying on the system-wide store.
Vulnerability scanners may report this CVE on any RouterOS version. As described above, the actual exposure depends on your configuration.
MikroTik always recommends keeping RouterOS devices up to date, using a separate CA for each purpose, and removing CA certificates that are no longer needed from the router.
Contact us about vulnerabilities