CVE-2026-56719

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
Configurations

No configuration.

History

16 Sep 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-09-16 14:17

Updated : 2026-09-16 16:17


NVD link : CVE-2026-56719

Mitre link : CVE-2026-56719

CVE.ORG link : CVE-2026-56719


JSON object : View

Products Affected

No product.

CWE
CWE-125

Out-of-bounds Read