| CVE | CVE-2026-93345 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 · CVSS 4.0 8.7 |
| Weakness | CWE-1284 |
| Affected versions | <= 7.24.2 |
| Fixed version | 7.25beta4 |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2026-09-22 |
What is the CVE-2026-93345 vulnerability?
CVE-2026-93345 is an improper input validation flaw (CWE-1284: Improper Validation of Specified Quantity in Input) present in the NLRI iterators for labelled-VPN in the routing service. An unauthenticated on-path attacker can send a malformed BGP UPDATE message with a prefix-length value lower than the minimum valid for a labelled-VPN NLRI, which passes validation but describes a route with a negative-length address portion. Repeatedly sending this packet can indefinitely hang the BGP plane, causing the session to terminate without sending a NOTIFICATION message and resulting in a service malfunction on the device.
Which RouterOS versions are vulnerable?
The vulnerable versions are all those less than or equal to 7.24.2, including the long-term release 7.23.5. The fixed version is 7.25beta4, which is a development version: the stable and long-term releases listed among the affected versions remain vulnerable, and an administrator must not install a beta in production without assessing its impact.
Is my router at risk?
A router is exposed if the BGP service is active and reachable from untrusted networks. The flaw specifically concerns BGP: the BGP session must be accepted only from expected peers, and filtering on port 179 reduces exposure. If the router does not have active BGP sessions towards external or untrusted networks, the risk is minimal.
Is the CVE-2026-93345 vulnerability actively exploited?
As of the date of the article, there is no evidence that the vulnerability is being exploited. CISA does not include it in the KEV catalog, and ENISA does not report it as exploited.
How to protect the router from CVE-2026-93345?
The primary mitigation is to update to a fixed version, but since the fix is only available in 7.25beta4 (a development version), in production you must limit the exposure of the BGP service: accept BGP sessions only from authorized peers and apply filters on port 179 to reduce the attack surface. Monitor for the availability of a stable or long-term release that includes the fix.
Which RouterOS commands are needed to mitigate CVE-2026-93345?
Temporary mitigation: bgp service
The flaw concerns BGP. The BGP session must be accepted only from expected peers: filtering on port 179 reduces exposure.
# elenca i peer legittimi
/ip firewall address-list add list=bgp-peers address=203.0.113.1 comment="peer esempio"
# scarta le connessioni BGP da chiunque altro
/ip firewall filter add chain=input protocol=tcp dst-port=179 \
src-address-list=!bgp-peers action=drop place-before=0 comment="solo peer BGP"
Update RouterOS
The only definitive fix is an update. First, save the configuration; the installation reboots the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
Does CVE-2026-93345 require authentication to be exploited?
No, CVE-2026-93345 can be exploited by an unauthenticated on-path attacker who sends a malformed BGP UPDATE message.
What is the CVSS score for CVE-2026-93345?
The CVSS v3.1 score is 7.5 (HIGH) and the CVSS v4.0 score is 8.7 (HIGH), both assigned by disclosure@vulncheck.com.
Is the 7.23.5 long-term version vulnerable to CVE-2026-93345?
Yes, the long-term release 7.23.5 is included in the affected versions and remains vulnerable; the fix is only present in 7.25beta4, a development version.
Is CVE-2026-93345 listed in the CISA KEV catalog?
No, CVE-2026-93345 is not included in the CISA KEV catalog as of the date of the article.



