CVE-2026-93345
Received Received - Intake

Improper Input Validation in MikroTik RouterOS BGP Service

Vulnerability report for CVE-2026-93345, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: VulnCheck

Description

MikroTik RouterOS before 7.25beta4 contains an improper input validation vulnerability in the labelled-VPN NLRI iterators of the routing service that allows an unauthenticated on-path attacker to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with a prefix-length value below the minimum valid for a labelled-VPN NLRI, which passes validation while describing a route with a negative-length address portion. Attackers can repeatedly send a single BGP UPDATE packet carrying a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to indefinitely hold down the BGP plane, causing session termination without a NOTIFICATION and triggering a service malfunction on the device.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mikrotik routeros to 7.25beta4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1284 The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper input validation flaw in MikroTik RouterOS versions before 7.25beta4. It affects the BGP service's labelled-VPN NLRI iterators, allowing an unauthenticated attacker on the network path to crash the BGP service by sending a malformed MP_REACH_NLRI UPDATE message with an invalid prefix-length value. The message passes validation even though it describes a route with a negative-length address portion, causing the BGP plane to malfunction and terminate sessions without proper notification.

Detection Guidance

Monitor BGP service logs for crashes or session terminations without NOTIFICATION messages. Check for malformed MP_REACH_NLRI UPDATE messages with prefix-length values below the minimum for labelled-VPN NLRI. Use network monitoring tools to detect repeated BGP UPDATE packets containing VPNv4 or VPNv6 NLRI with out-of-bounds prefix-lengths.

Impact Analysis

This vulnerability can cause the BGP service on affected MikroTik RouterOS devices to crash repeatedly. Attackers can send a single malicious BGP UPDATE packet to indefinitely disrupt routing operations, leading to session termination and service malfunction. This can result in network instability, loss of connectivity, and potential denial of service for the entire network.

Mitigation Strategies

Upgrade RouterOS to version 7.25beta4 or later immediately. Apply the latest security patches from MikroTik. Monitor BGP service stability and session states closely after updating. Ensure backups of configurations are available before upgrading.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93345. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart