PT-2026-93715 · Mikrotik · Routeros
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
MikroTik RouterOS versions prior to 7.24
Description
An out-of-bounds read exists in the userspace SMB daemon. Unauthenticated attackers can read beyond the end of the request buffer by providing a crafted
uniPwdLen field value within a minimal SMB1 SessionSetupAndX frame. This issue occurs in the SessionSetupAndX handler before credential validation, which may expose sensitive memory contents.Recommendations
Update MikroTik RouterOS to version 7.24 or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Routeros