CVE-2025-6563 - CVE House
Back to Database
Status published Medium CVE-2025-6563

Cross-site scripting via dst parameter in RouterOS WiFi hotspot

Vulnerability Description

A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request used to login, can also be converted to a GET request, allowing an attacker to send a specifically crafted URL that automatically logs in the victim (into the attacker's account) and triggers the payload.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-6563

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

RouterOS
Vulnerable Versions:
0

Timeline

Official Publish: July 3rd, 2025
Last Modified: July 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)