# CVE-2026-89020

## Summary

- **CVE ID:** CVE-2026-89020
- **Severity:** MEDIUM
- **CVSS Score:** 5.3 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-121
- **Published:** Sep 14, 2026
- **Last Modified:** Sep 16, 2026

## Description

MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in the mtget binary's TFTP RRQ builder function that allows authenticated users to crash the mtget worker process by supplying a URL path of 507 bytes or more to the /tool fetch command; the first write outside the 528-byte buffer occurs at 505 bytes. Attackers can trigger the overflow by issuing a fetch command with a crafted tftp:// URL path, which causes an unbounded rep movsb instruction to overwrite saved registers at a deterministic offset, crashing the process without requiring a reachable TFTP server or elevated privileges beyond read-only group membership.

## Affected Products

- MikroTik — RouterOS (0)
- MikroTik — RouterOS (7.24.0)

## References

- [CNA](https://mikrotik.com/supportsec/september-2026-vulnerability)
- [CNA](https://www.vulncheck.com/advisories/mikrotik-routeros-stack-buffer-overflow-via-tftp-url-path)
- [CNA](https://forum.mikrotik.com/t/7-24-2-stable-is-released/272800)
- [CNA](https://forum.mikrotik.com/t/7-23-4-long-term-is-released/272801)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.24%
- **EPSS Percentile:** 15.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._