Improper Input Validation in MikroTik RouterOS Affects BGP Service
CVE-2026-93345

8.7HIGH

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-93345?

MikroTik RouterOS versions before 7.25beta4 contain an improper input validation flaw in the handling of labelled-VPN NLRI iterators within the routing service. This vulnerability enables an unauthenticated attacker positioned on the network path to disrupt the BGP service. By transmitting a malformed MP_REACH_NLRI UPDATE message, the attacker can specify an out-of-bounds prefix length that falsely passes initial validation checks. Such attacks can lead to continuous BGP session terminations without notifications, causing significant disruptions in the routing service and potentially leaving devices vulnerable to further exploitation.

Affected Version(s)

RouterOS 0 <= 7.24.2

RouterOS 7.25beta4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kazuma Matsumoto, a security researcher at GMO Cybersecurity by IERAE, Inc.
.