PT-2026-91400 · Mikrotik · Routeros

CVE-2026-89020

·

Published

2026-09-14

·

Updated

2026-09-16

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions RouterOS versions prior to 7.23.4 (long-term) RouterOS versions prior to 7.24.2 (stable)
Description A stack-based buffer overflow exists in the TFTP RRQ builder function of the mtget binary. Authenticated users with read-only group membership can crash the mtget worker process by providing a URL path of 507 bytes or more to the /tool fetch endpoint. This occurs because an unbounded rep movsb instruction overwrites saved registers at a deterministic offset when a crafted tftp:// URL path is used. The process can be crashed without the need for a reachable TFTP server.
Recommendations Update to version 7.23.4 (long-term) or newer. Update to version 7.24.2 (stable) or newer. Avoid using the /tool fetch command with long tftp:// URL paths until the system is updated.

Fix

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-89020

Affected Products

Routeros