Impact
The vulnerability is a stack‑based buffer overflow in the mtget binary’s TFTP request‑response generator. By supplying a TFTP URL path that is 507 bytes or longer to the /tool fetch command, an attacker can make the unbounded memory copy overwrite saved registers, causing the mtget worker process to crash. The exploit requires an authenticated user with read‑only group membership, and does not need a reachable TFTP server. The impact is limited to a local denial of service by crashing the process; no remote code execution or data disclosure is possible.
Affected Systems
MikroTik RouterOS versions prior to 7.23.4 in the long‑term branch and prior to 7.24.2 in the stable branch are affected. The issue is confined to the mtget binary that handles TFTP operations.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires authenticated users with specific group rights and only triggers a service crash, the overall risk is considered moderate to low, and the likelihood of exploitation is limited by the narrow privilege requirement.
OpenCVE Enrichment