PT-2026-97696 · D Link · Dir-825

·

CVE-2026-96891

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DIR-825 version 3.00b32
Description A remote attack is possible due to an out-of-bounds write in the rp-l2tp component. The issue exists within the tunnel set params() function located in the tunnel.c file, where manipulation of the peer hostname argument triggers the flaw.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15204
CVE-2026-96891

Affected Products

Dir-825