Record summary

CVE-2025-6563 has a selected CVSS score of 4.8 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

A cross-site scripting vulnerability is present in the hotspot of MikroTik's RouterOS on versions below 7.19.2. An attacker can inject the `javascript` protocol in the `dst` parameter. When the victim browses to the malicious URL and logs in, the XSS executes. The POST request used to login, can also be converted to a GET request, allowing an attacker to send a specifically crafted URL that automatically logs in the victim (into the attacker's account) and triggers the payload.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 3, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE ListBefore 7.19.2affected

Proofs of concept

2

Catalogued exploits

ExploitDBMikroTik RouterOS 7.19.1 - Reflected XSSExploitDB exploitby Prak SokcheaNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubpraksokchea/CVE-2025-6563Repository PoCby praksokcheaStars: 0Not analyzed3 files

852.4 KiB

GitHub

PoC details

References

2