Description
MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory.
Published: 2026-09-16
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via Heap Corruption
Action: Apply Patch
AI Analysis

Impact

A heap memory corruption flaw exists in the userspace SMB daemon of MikroTik RouterOS. An attacker can send a malformed SMB1 SessionSetupAndX request with a crafted uniPwdLen field that triggers an integer underflow, causing the value to be used as a copy length for a memory copy operation into a smaller buffer. This corrupts adjacent heap memory and can enable arbitrary code execution on the device. The flaw originates from improper size validation and can lead to arbitrary code execution, denial of service, or other unintended behavior.

Affected Systems

All MikroTik RouterOS installations running a version prior to 7.24 are affected. The issue is tied to the SMB1 implementation in older RouterOS releases and is not present in 7.24 or newer.

Risk and Exploitability

The flaw has a CVSS score of 8.2, indicating high severity. The EPSS score is below 1%, suggesting a low but nonzero likelihood of exploitation in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog, and the vulnerability requires a remote attacker to have network access to the SMB1 service, which is typically restricted or disabled by default. While the technical barriers are moderate, the potential impact warrants proactive mitigation.

Generated by OpenCVE AI on September 18, 2026 at 02:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade MikroTik RouterOS to version 7.24 or later, which contains the fix for the heap corruption flaw.
  • As a temporary measure, disable the SMB1 protocol or block SMB traffic on the device to eliminate the attack surface if an upgrade cannot be performed immediately.
  • Verify that the device’s SMB service is no longer reachable from untrusted networks and monitor logs for suspicious SMB activity to ensure the vulnerability is mitigated.

Generated by OpenCVE AI on September 18, 2026 at 02:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Mikrotik
Mikrotik routeros
Vendors & Products Mikrotik
Mikrotik routeros

Wed, 16 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Description MikroTik RouterOS before 7.24 contains a heap memory corruption vulnerability in the userspace SMB daemon that allows remote attackers to corrupt adjacent heap memory by supplying a crafted uniPwdLen value in the SMB1 SessionSetupAndX handler. An attacker can send a malformed SMB1 request with a uniPwdLen field that triggers an integer underflow, causing the resulting value to be used as the copy length in a memory copy operation into a smaller heap buffer, corrupting adjacent heap memory.
Title MikroTik RouterOS < 7.24 Heap Corruption via SMB1 SessionSetupAndX
Weaknesses CWE-122
CWE-191
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Mikrotik Routeros
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-01T15:21:51.527Z

Reserved: 2026-09-10T16:23:54.472Z

Link: CVE-2026-89028

cve-icon Vulnrichment

Updated: 2026-09-17T19:16:38.246Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T14:17:12.887

Modified: 2026-09-24T21:04:40.340

Link: CVE-2026-89028

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T02:45:17Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow

  • CWE-191

    Integer Underflow (Wrap or Wraparound)