Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-56719— MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX

Quick assessment

Affected
MikroTik RouterOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MikroTik RouterOS 7.24 及更早版本中的用户态 SMB 守护进程存在一个越界读取漏洞。未认证的 attackers 通过构造包含特定 字段值的极简 SMB1 SessionSetupAndX 帧,可以读取请求缓冲区末端之外的内存。该越界读取发生在 SessionSetupAndX 处理函数中,且在凭据验证之前,可能会暴露敏感的内存内容。

CVSS 6.5 · Medium

Possible ATT&CK Techniques 1 AI

T1515

Affected Version Matrix 3

VendorProduct Version RangeStatus
MikroTik RouterOS ≤ 6.49.18 affected
7.0.0≤ 7.11.2 affected
7.24.0 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-56719

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX
Source: CVE Program / CVE List V5
Vulnerability Description
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存读
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MikroTik RouterOS 0 ~ 6.49.18 -

II. Public POCs for CVE-2026-56719

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-56719

登录查看更多情报信息。

Vendor Advisories for CVE-2026-56719 (1)

Vendor Pages for CVE-2026-56719 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-56719

No comments yet


Leave a comment