SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-89020

MEDIUM · CVSS 4.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

MikroTik RouterOS versions prior to 7.23.4 (long-term) and 7.24.2 (stable) are vulnerable to a stack-based buffer overflow in the mtget binary's TFTP RRQ builder function, which can be exploited by authenticated users to crash the mtget worker process. By supplying a specially crafted URL path of 507 bytes or more to the /tool fetch command, attackers can trigger the overflow, leading to process instability without needing elevated privileges. Organizations using affected MikroTik RouterOS versions should prioritize patching to mitigate the risk of service disruption.

CVE
CVE-2026-89020
Severity
MEDIUM
CVSS
4.3
EPSS
0.24%

Original NVD Description

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write outside the 528-byte buffer occurs at 505 bytes. Attackers can trigger the overflow by issuing a fetch command with a crafted tftp:// URL path, which causes an unbounded rep movsb instruction to overwrite saved registers at a deterministic offset, crashing the process without requiring a reachable TFTP server or elevated privileges beyond read-only group membership.