Skip to finding
important · Wi-Fi — RouterOS

A RouterOS read-only operator can control native execution in the x86 mtget helper.

Affects

MikroTik RouterOS, the operating system used by MikroTik routers and CHR virtual routers; exploit control was demonstrated on x86 CHR.

A test-policy account invokes /tool fetch with an overlong TFTP pathname, overwriting saved EIP and the post-return stack.

Detail and 2 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 5, 2026