CVE-2026-89020: MikroTik RouterOS Stack Buffer Overflow via TFTP URL Path

Published Sep 14, 2026
·
Updated

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write outside the 528-byte buffer occurs at 505 bytes. Attackers can trigger the overflow by issuing a fetch command with a crafted tftp:// URL path, which causes an unbounded rep movsb instruction to overwrite saved registers at a deterministic offset, crashing the process without requiring a reachable TFTP server or elevated privileges beyond read-only group membership.

Affected Software

1 affected component
Mikrotik RouterOS<7.23.4, <7.24.2

Event History

Sep 14, 2026
CVE Published
via MITRE·06:02 PM
Data Sourced
via MITRE·06:02 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which RouterOS releases are affected?

RouterOS releases before 7.23.4 on the long-term branch and before 7.24.2 on the stable branch are affected.

2

What access does an attacker need to trigger the crash?

An attacker needs authenticated RouterOS access with read-only group membership or higher. No elevated privileges beyond that membership are required.

3

Does exploitation require a TFTP server to be reachable?

No. The crafted tftp:// URL path triggers the overflow during request construction, so a reachable TFTP server is not required.

4

What is the practical impact of exploitation?

A user can crash the mtget worker process. The provided data describes availability impact only and does not indicate confidentiality or integrity impact.

5

What input indicates an attempted trigger?

The trigger is a /tool fetch command using a crafted tftp:// URL path of 507 bytes or more. The first write beyond the 528-byte buffer occurs at a path length of 505 bytes.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203