Beveiligingsadvies

CVE-2026-56719

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-16 13:07:38
Laatst bijgewerkt 2026-09-16 15:52:01
Toegewezen door VulnCheck
CVSS-score 6.5
Status PUBLISHED

Beschrijving

MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.