Impact
An SMB daemon in MikroTik RouterOS can be sent a crafted SMB1 SessionSetupAndX frame that contains a deceptive uniPwdLen field. The code that processes this frame reads the field without validating its bounds, resulting in an out‑of‑bounds read from memory before any credential validation is performed. An unauthenticated attacker can therefore read beyond the intended request buffer and exfiltrate portions of system memory that may contain sensitive information. The primary consequence is the potential leakage of confidential data, but there is no indication of execution or modification of system state based on the current description.
Affected Systems
Affected systems include MikroTik RouterOS devices running any version earlier than 7.24. The vulnerability is in the userspace SMB daemon bundled with these releases, so any MikroTik router or access point that has RouterOS <7.24 and has SMB1 enabled is at risk. Devices that use newer firmware (7.24 or later) are no longer affected.
Risk and Exploitability
The CVSS base score is 6.3, indicating moderate severity. The EPSS score is below 1%, meaning that the likelihood of exploitation is low. The vulnerability is not listed in CISA’s KEV catalogue. Attackers can exploit the flaw by sending a malicious SMB1 SessionSetupAndX packet over the network to the target router; no authentication or elevated privileges are required because the out‑of‑bounds read occurs before any credential checks. If SMB1 is disabled or inaccessible, the attack surface is effectively removed.
OpenCVE Enrichment