{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/routeros--7.25beta4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mikrotik:routeros:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93345"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["RouterOS (\u003c 7.25beta4)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["MikroTik"],"content_html":"\u003cp\u003eMikroTik RouterOS versions prior to 7.25beta4 contain an improper input validation vulnerability within the labelled-VPN NLRI iterators of the BGP routing service. This flaw allows an unauthenticated, on-path attacker to send a malformed MP_REACH_NLRI UPDATE message containing a prefix-length value that is below the minimum required for a valid labelled-VPN NLRI. Because the router fails to properly validate this value, it interprets the packet as describing a route with a negative-length address portion, leading to a service crash. Attackers can leverage this by repeatedly sending a single BGP UPDATE packet containing a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to cause indefinite BGP plane instability and repeated session terminations, effectively creating a persistent denial-of-service (DoS) condition on the affected device.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service condition, rendering the BGP service on the targeted MikroTik device unstable or non-functional. This impacts network routing availability for any traffic relying on the BGP session handled by the vulnerable process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of internet-facing or peer-connected MikroTik devices. Upgrade all affected instances of RouterOS to version 7.25beta4 or later to address the input validation flaw identified in CVE-2026-93345.\u003c/p\u003e\n","date_modified":"2026-09-22T18:39:23Z","date_published":"2026-09-22T18:39:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mikrotik-bgp-dos/","summary":"An unauthenticated, on-path attacker can trigger a denial-of-service condition in MikroTik RouterOS by sending malformed BGP UPDATE packets with out-of-bounds prefix-lengths.","title":"CVE-2026-93345: Improper Input Validation in MikroTik RouterOS BGP Service","url":"https://feed.craftedsignal.io/briefs/2026-09-mikrotik-bgp-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - RouterOS (\u003c 7.25beta4)","version":"https://jsonfeed.org/version/1.1"}