Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-89020— MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path

Quick assessment

Affected
MikroTik RouterOS
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MikroTik RouterOS 在 7.23.4(长期支持版本)之前以及 7.24.2(稳定版本)之前,其 二进制文件中的 TFTP RRQ 构建函数存在一个基于栈的缓冲区溢出漏洞。经过认证的用户可以通过向 命令提供长度大于等于 507 字节的 URL 路径,导致 工作进程崩溃;首次超出 528 字节缓冲区范围的写入发生在输入长度为 505 字节时。攻击者可以通过发送包含构造的 URL 路径的 fetch 命令来触发该溢出,导致一条无界定的 指令在确定性的偏移处覆盖保存的寄存器,从而使进程崩溃。此漏洞的利用不需

CVSS 4.3 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
MikroTik RouterOS < 7.23.4 affected
7.24.0< 7.24.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-89020

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path
Source: CVE Program / CVE List V5
Vulnerability Description
MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write outside the 528-byte buffer occurs at 505 bytes. Attackers can trigger the overflow by issuing a fetch command with a crafted tftp:// URL path, which causes an unbounded rep movsb instruction to overwrite saved registers at a deterministic offset, crashing the process without requiring a reachable TFTP server or elevated privileges beyond read-only group membership.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
MikroTik RouterOS 0 ~ 7.23.4 -

II. Public POCs for CVE-2026-89020

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-89020

登录查看更多情报信息。

Vendor Advisories for CVE-2026-89020 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-89020

No comments yet


Leave a comment