๐Ÿ” CVE Alert

CVE-2026-93345

HIGH 7.5

MikroTik RouterOS < 7.25beta4 Improper Input Validation DoS via BGP Labelled-VPN NLRI

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with a negative-length address portion. Attackers can repeatedly send a single BGP UPDATE packet carrying a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to indefinitely hold down the BGP plane, causing session termination without a NOTIFICATION and triggering a service malfunction on the device.

CWE CWE-1284
Vendor mikrotik
Product routeros
Published Sep 22, 2026
Last Updated Sep 22, 2026
Stay Ahead of the Next One

Get instant alerts for mikrotik routeros

Be the first to know when new high vulnerabilities affecting mikrotik routeros are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

MikroTik / RouterOS
7.21.5 < 7.25beta4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
forum.mikrotik.com: https://forum.mikrotik.com/t/7-25beta-development-is-released/272788 vulncheck.com: https://www.vulncheck.com/advisories/mikrotik-routeros-improper-input-validation-dos-via-bgp-labelled-vpn-nlri

Credits

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.