Junglewise Threat Intelligence

CVE-2026-93345: MikroTik RouterOS improper input validation in BGP labelled-VPN NLRI

CVE-2026-93345 · Severity: high · CVSS 7.5 · Published 2026-09-22

Technologies: MikroTik RouterOS. Vendors: MikroTik.

Executive brief

MikroTik RouterOS is a network operating system that runs on routers and manages network traffic. An unauthenticated attacker positioned on the network path can crash the BGP (Border Gateway Protocol) service by sending malformed routing messages, causing the router to drop BGP sessions and disrupting network connectivity. An attacker can repeatedly exploit this to keep the BGP service down indefinitely.

Technical details

The vulnerability is an improper input validation flaw in the labelled-VPN NLRI iterators of the BGP routing service. An unauthenticated on-path attacker can send a malformed MP_REACH_NLRI UPDATE message with an out-of-bounds prefix-length value for VPNv4 or VPNv6 routes, causing negative-length address calculations that trigger a service crash. Exploitation requires network access to the BGP session (adjacent network vector) and does not require authentication.

Affected products

  • MikroTik RouterOS before 7.25beta4; 7.24.2 and 7.23.5 remain affected

Timeline

  • 2026-09-22: disclosed: CVE-2026-93345 published
  • 2026-09-10: patched: Fix included in 7.25beta4 development release

References

Related threats