CVE-2026-56719
Severity CVSS v4.0:
MEDIUM
Type:
CWE-125
Out-of-bounds Read
Publication date:
16/09/2026
Last modified:
24/09/2026
Description
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Impact
Base Score 4.0
6.30
Severity 4.0
MEDIUM
Base Score 3.x
6.50
Severity 3.x
MEDIUM


