Impact
A heap memory corruption flaw exists in the userspace SMB daemon of MikroTik RouterOS. An attacker can send a malformed SMB1 SessionSetupAndX request with a crafted uniPwdLen field that triggers an integer underflow, causing the value to be used as a copy length for a memory copy operation into a smaller buffer. This corrupts adjacent heap memory and can enable arbitrary code execution on the device. The flaw originates from improper size validation and can lead to arbitrary code execution, denial of service, or other unintended behavior.
Affected Systems
All MikroTik RouterOS installations running a version prior to 7.24 are affected. The issue is tied to the SMB1 implementation in older RouterOS releases and is not present in 7.24 or newer.
Risk and Exploitability
The flaw has a CVSS score of 8.2, indicating high severity. The EPSS score is below 1%, suggesting a low but nonzero likelihood of exploitation in the wild. It is not listed in the CISA Known Exploited Vulnerabilities catalog, and the vulnerability requires a remote attacker to have network access to the SMB1 service, which is typically restricted or disabled by default. While the technical barriers are moderate, the potential impact warrants proactive mitigation.
OpenCVE Enrichment