Executive brief
MikroTik RouterOS is a network operating system that runs on routers and manages network traffic. An unauthenticated attacker positioned on the network path can crash the BGP (Border Gateway Protocol) service by sending malformed routing messages, causing the router to drop BGP sessions and disrupting network connectivity. An attacker can repeatedly exploit this to keep the BGP service down indefinitely.
Technical details
The vulnerability is an improper input validation flaw in the labelled-VPN NLRI iterators of the BGP routing service. An unauthenticated on-path attacker can send a malformed MP_REACH_NLRI UPDATE message with an out-of-bounds prefix-length value for VPNv4 or VPNv6 routes, causing negative-length address calculations that trigger a service crash. Exploitation requires network access to the BGP session (adjacent network vector) and does not require authentication.
Affected products
- MikroTik RouterOS before 7.25beta4; 7.24.2 and 7.23.5 remain affected
Timeline
- 2026-09-22: disclosed: CVE-2026-93345 published
- 2026-09-10: patched: Fix included in 7.25beta4 development release