Vulnerability Description
MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a crafted uniPwdLen field value in a minimal SMB1 SessionSetupAndX frame. The out-of-bounds read occurs in the SessionSetupAndX handler before any credential validation, potentially exposing sensitive memory contents.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://forum.mikrotik.com/t/7-24-stable-is-released/272381
- https://www.vulncheck.com/advisories/mikrotik-routeros-out-of-bounds-read-via-sm
FAQ
What is CVE-2026-56719?
CVE-2026-56719 is a vulnerability with a CVSS score of 6.5 (MEDIUM). MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unauthenticated attackers to read beyond the end of the request buffer by supplying a...
How severe is CVE-2026-56719?
CVE-2026-56719 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-56719?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.