CVE-2018-5951: MikroTik RouterOS Denial of Service Vulnerability

So you know it is not caused by this particular problem.
Then why do you add your comment to this topic? That is just useless.

You should rather focus on the problem you have at hand.

Dear all, just flagging that this vuln still shows as affecting the most recent version v7.14.2 via the json query:

https://services.nvd.nist.gov/rest/json/cves/2.0?cpeName=cpe:2.3:o:mikrotik:routeros:7.14.2:*:*:*:*:*:*:*

Assuming is fixed, which version was this fixed in?

As NVD would need to add the versionEndIncluding field.

"nodes": [
{
    "operator": "OR",
    "negate": false,
    "cpeMatch": [
    {
        "vulnerable": true,
        "criteria": "cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*",
        "matchCriteriaId": "7DED322B-DACD-4FD1-8EBE-BF3B6E897921"
    }
    ]
}

We were not able to reproduce this issue in 6.47.10/6.48.5 versions. There have been other IPv6 related fixes since then, for example, https://blog.mikrotik.com/software/cve-2018-19298-cve-2018-19299-ipv6-resource-exhaustion.html
It is a false positive.