CVE-2026-56719

RouterOS: Out-of-bounds Read (CVE-2026-56719)

mediumEPSS 0.4%

Description

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

MikroTikRouterOS
< 7.24fixed in 7.24

Metrics

6.5
Source: nvd-v3
31.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-09-16 13:07 UTC
CWE-125

Weakness classes (CWE)

  • CWE-125Base

    Out-of-bounds Read

    The product reads data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-09-16 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-56719","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
  2. New CVE Received2026-09-16 14:17 UTC· disclosure@vulncheck.com
    • Description: MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
    • CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
    • CWE: CWE-125