CVE-2026-56719
RouterOS: Out-of-bounds Read (CVE-2026-56719)
mediumEPSS 0.4%
Description
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
MikroTikRouterOS
< 7.24fixed in 7.24Metrics
Show all metrics
Severity
medium
70.39
no public PoC known
6.5
6.3
Published
2026-09-16 13:07 UTC
CWE-125
Weakness classes (CWE)
CWE-125Base
Out-of-bounds Read
The product reads data past the end, or before the beginning, of the intended buffer.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-09-16 16:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-56719","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-09-16 14:17 UTC· disclosure@vulncheck.com
- Description: MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
- CVSS V4.0: AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- CWE: CWE-125