<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>RouterOS (&lt; 7.25beta4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/routeros--7.25beta4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 22 Sep 2026 18:39:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/routeros--7.25beta4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>CVE-2026-93345: Improper Input Validation in MikroTik RouterOS BGP Service</title><link>https://feed.craftedsignal.io/briefs/2026-09-mikrotik-bgp-dos/</link><pubDate>Tue, 22 Sep 2026 18:39:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-mikrotik-bgp-dos/</guid><description>An unauthenticated, on-path attacker can trigger a denial-of-service condition in MikroTik RouterOS by sending malformed BGP UPDATE packets with out-of-bounds prefix-lengths.</description><content:encoded><![CDATA[<p>MikroTik RouterOS versions prior to 7.25beta4 contain an improper input validation vulnerability within the labelled-VPN NLRI iterators of the BGP routing service. This flaw allows an unauthenticated, on-path attacker to send a malformed MP_REACH_NLRI UPDATE message containing a prefix-length value that is below the minimum required for a valid labelled-VPN NLRI. Because the router fails to properly validate this value, it interprets the packet as describing a route with a negative-length address portion, leading to a service crash. Attackers can leverage this by repeatedly sending a single BGP UPDATE packet containing a VPNv4 or VPNv6 NLRI with an out-of-bounds prefix-length to cause indefinite BGP plane instability and repeated session terminations, effectively creating a persistent denial-of-service (DoS) condition on the affected device.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a persistent denial-of-service condition, rendering the BGP service on the targeted MikroTik device unstable or non-functional. This impacts network routing availability for any traffic relying on the BGP session handled by the vulnerable process.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of internet-facing or peer-connected MikroTik devices. Upgrade all affected instances of RouterOS to version 7.25beta4 or later to address the input validation flaw identified in CVE-2026-93345.</p>
]]></content:encoded><category domain="severity">low</category><category domain="type">advisory</category></item></channel></rss>