PT-2026-91400 · Mikrotik · Routeros
CVE-2026-89020
·
Published
2026-09-14
·
Updated
2026-09-16
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
RouterOS versions prior to 7.23.4 (long-term)
RouterOS versions prior to 7.24.2 (stable)
Description
A stack-based buffer overflow exists in the TFTP RRQ builder function of the
mtget binary. Authenticated users with read-only group membership can crash the mtget worker process by providing a URL path of 507 bytes or more to the /tool fetch endpoint. This occurs because an unbounded rep movsb instruction overwrites saved registers at a deterministic offset when a crafted tftp:// URL path is used. The process can be crashed without the need for a reachable TFTP server.Recommendations
Update to version 7.23.4 (long-term) or newer.
Update to version 7.24.2 (stable) or newer.
Avoid using the
/tool fetch command with long tftp:// URL paths until the system is updated.Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Routeros