A buffer overflow vulnerability has been identified in the “fetch” tool of RouterOS (/tool fetch), when it is given a very long tftp:// address. A logged-in user can use this to crash the fetch process. The issue has been assigned CVE-2026-89020.
Who is affected: RouterOS versions 6 and 7 before the fixed releases listed below. To trigger the issue, the attacker needs a valid username and password on the router. Even a read-only user can trigger it, so this matters for devices with multiple user accounts or shared logins.
Although the public report describes a crash, we treat this issue seriously, because memory corruption issues of this type can sometimes be abused for more than a crash. We recommend upgrading rather than relying on the limited user rights of your accounts.
This issue is fixed in:
Users are advised to upgrade to one of these versions or any later release.
Until you upgrade, review the user accounts on your router, remove accounts that are no longer needed, and make sure management services are not reachable from untrusted networks.
MikroTik always recommends keeping RouterOS devices up to date and using a strong firewall to limit exposure from untrusted networks.
Contact us about vulnerabilities