CVE-2026-89028 | MikroTik RouterOS up to 6.49.18/7.11.2/7.23.x SMB1 SessionSetupAndX uniPwdLen integer underflow

SecurityVulns

A vulnerability was found in MikroTik RouterOS up to 6.49.18/7.11.2/7.23.x and classified as critical. The affected element is an unknown function of the component SMB1 SessionSetupAndX Handler. The manipulation of the argument uniPwdLen results in integer underflow.

This vulnerability is identified as CVE-2026-89028. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More