Description
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Published: 2026-09-16
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Data Exposure
Action: Apply Patch
AI Analysis

Impact

An SMB daemon in MikroTik RouterOS can be sent a crafted SMB1 SessionSetupAndX frame that contains a deceptive uniPwdLen field. The code that processes this frame reads the field without validating its bounds, resulting in an out‑of‑bounds read from memory before any credential validation is performed. An unauthenticated attacker can therefore read beyond the intended request buffer and exfiltrate portions of system memory that may contain sensitive information. The primary consequence is the potential leakage of confidential data, but there is no indication of execution or modification of system state based on the current description.

Affected Systems

Affected systems include MikroTik RouterOS devices running any version earlier than 7.24. The vulnerability is in the userspace SMB daemon bundled with these releases, so any MikroTik router or access point that has RouterOS <7.24 and has SMB1 enabled is at risk. Devices that use newer firmware (7.24 or later) are no longer affected.

Risk and Exploitability

The CVSS base score is 6.3, indicating moderate severity. The EPSS score is below 1%, meaning that the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalogue. Attackers can exploit the flaw by sending a malicious SMB1 SessionSetupAndX packet over the network to the target router; no authentication or elevated privileges are required because the out‑of‑bounds read occurs before any credential checks. If SMB1 is disabled or inaccessible, the attack surface is effectively removed.

Generated by OpenCVE AI on September 18, 2026 at 03:19 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade RouterOS to version 7.24 or later
  • Disable SMB1 protocol if it is not needed for legacy devices
  • Block SMB1 traffic (TCP port 445) to the router using firewall or network segmentation

Generated by OpenCVE AI on September 18, 2026 at 03:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 05:15:00 +0000

Type Values Removed Values Added
First Time appeared Mikrotik
Mikrotik routeros
Vendors & Products Mikrotik
Mikrotik routeros

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Title MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:20:03.940Z

Reserved: 2026-06-22T18:48:39.687Z

Link: CVE-2026-56719

cve-icon Vulnrichment

Updated: 2026-09-16T15:51:57.447Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:05.483

Modified: 2026-09-24T20:44:42.207

Link: CVE-2026-56719

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:30:02Z

Weaknesses