
SMB
SMB file sharing on the router: all dojo articles on this topic.
Image generated locally with ComfyUI from randomly selected elements. How the images are created

Out-of-bounds Read in the SMB Daemon of RouterOS
CVE-2026-56719 is an Out-of-bounds Read vulnerability in the SMB daemon of MikroTik RouterOS. It affects versions up to 7.11.2 and 6.49.18, allowing an unauthenticated attacker to read sensitive memory via a manipulated SMB1 frame. Updating to version 7.24.0 resolves the issue; alternatively, disabling the SMB service eliminates the exposure.
SecurityHeap corruption in the SMB daemon of RouterOS
CVE-2026-89028 is a heap memory corruption vulnerability in the SMB daemon of RouterOS that allows a remote attacker to cause a denial of service. It affects versions up to 7.11.2 and 6.49.18; the fix is available in version 7.24.0. To mitigate the risk, you must update to 7.24.0 or disable the SMB service if not in use.
SecurityDoS Vulnerability in the SMB Service of RouterOS
CVE-2024-54952 is a memory corruption vulnerability in the SMB service of MikroTik RouterOS 6.40.5 that allows a remote unauthenticated attacker to cause a Denial of Service (DoS) by making the SMB service inaccessible. The version specified as affected is 6.40.5; corrective versions have not yet been announced. To mitigate the risk, you must disable the SMB service if it is not strictly necessary or update to the next stable release when available.
SecurityBuffer overflow in the SMB server of RouterOS
CVE-2020-22844 is a buffer overflow in the SMB server of RouterOS 6.47 that allows an unauthenticated attacker to cause a denial of service through malicious SMB requests. The vulnerability specifically affects version 6.47 and is not known to be actively exploited. To mitigate the risk, you must update the firmware or disable the SMB service if it is not in use.
SecurityInteger underflow in the RouterOS SMB server
CVE-2019-16160 is an integer underflow in the RouterOS SMB server that allows an unauthenticated remote attacker to crash the service. RouterOS versions prior to 6.45.5 are affected. To mitigate the risk, upgrade to a later version or disable the SMB service if not required.
SecuritySMB server crash in RouterOS
CVE-2020-11881 is an array index validation error in the RouterOS SMB server that allows a remote unauthenticated attacker to cause a service crash. It affects versions 6.41.3 through 6.46.5 and 7.x versions up to 7.0 Beta5. Immediate mitigation is to disable the SMB server if not strictly necessary, as the stable fixed version is not specified in the available data.
SecurityDenial of Service in the SMB service of RouterOS x86
CVE-2024-27686 allows a remote attacker to crash the device by sending malicious data packets to the SMB service on TCP port 445. This vulnerability affects RouterOS versions 6.40.5 through 6.49.10 for the x86 architecture. To mitigate the risk, you must disable the SMB service or upgrade to a 7.x version, as the fix is only available in the 7 series.
SecurityBuffer overflow in the SMB service of RouterOS
CVE-2018-7445 is a critical vulnerability (CVSS 9.8) in the SMB service of RouterOS that allows an unauthenticated attacker to execute code. It affects all RouterOS versions prior to 6.41.3. The vulnerability is listed in the CISA KEV catalog and requires applying updates according to the vendor's instructions.