๐Ÿ” CVE Alert

CVE-2026-56719

MEDIUM 6.5

MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.

CWE CWE-125
Vendor mikrotik
Product routeros
Published Sep 16, 2026
Last Updated Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for mikrotik routeros

Be the first to know when new medium vulnerabilities affecting mikrotik routeros are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
Low

Affected Versions

MikroTik / RouterOS
0 โ‰ค 6.49.18 7.0.0 โ‰ค 7.11.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
forum.mikrotik.com: https://forum.mikrotik.com/t/7-24-stable-is-released/272381 vulncheck.com: https://www.vulncheck.com/advisories/mikrotik-routeros-out-of-bounds-read-via-smb1-sessionsetupandx

Credits

eeee VulnCheck