CVE CVE-2026-89020
Severity MEDIUM · CVSS 3.1 4.3 · CVSS 4.0 5.3
Weakness CWE-121
Affected versions < 7.23.4, < 7.24.2
First non-vulnerable version 7.23.4, 7.24.2 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2026-09-14

What is the CVE-2026-89020 vulnerability?

The vulnerability consists of a stack-based buffer overflow in the TFTP RRQ builder function of the mtget binary. An authenticated user can cause the mtget worker process to crash by providing a URL path of 507 bytes or more to the /tool fetch command. The first out-of-bounds write from the 528-byte buffer occurs at 505 bytes. The attack exploits an unbounded rep movsb instruction that overwrites saved registers at a deterministic offset, causing the process to crash without requiring a reachable TFTP server or elevated privileges beyond membership in the read-only group.

Which RouterOS versions are vulnerable?

The vulnerable versions are all those prior to 7.23.4 (long-term) and 7.24.2 (stable). The fixed versions are 7.23.4 (long-term) and 7.24.2 (stable).

Is my router at risk?

A router is exposed if it is running a RouterOS version prior to 7.23.4 or 7.24.2 and if an authenticated user with at least read-only group privileges can execute the /tool fetch command with a malicious TFTP path. The vulnerability does not require the router to be reachable from untrusted networks for the initial attack, but it requires local or remote authentication of a user with the minimum privileges necessary to use the tool.

Is the CVE-2026-89020 vulnerability actively exploited?

As of the date of this article, there is no evidence that the vulnerability is being actively exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as exploited.

How to protect the router from CVE-2026-89020?

The only effective mitigation is to update RouterOS to version 7.23.4 (long-term) or version 7.24.2 (stable). No alternative configuration-based mitigations are available, as the vulnerability resides in the code of the mtget binary and is triggered by a legitimate system command.

Which RouterOS commands are needed to mitigate CVE-2026-89020?

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2026-89020 require authentication?

Yes, CVE-2026-89020 requires the attacker to be an authenticated user with at least read-only group privileges to execute the /tool fetch command.

What is the CVSS score for CVE-2026-89020?

The CVSS v3.1 score for CVE-2026-89020 is 4.3 (MEDIUM) and the CVSS v4.0 score is 5.3 (MEDIUM).

Is CVE-2026-89020 in the CISA KEV catalog?

No, CVE-2026-89020 is not in the CISA KEV catalog as of the date of this article.

Which versions fix CVE-2026-89020?

The versions that fix CVE-2026-89020 are 7.23.4 (long-term) and 7.24.2 (stable).

Official sources