PT-2026-99422 · D Link · Dir-895L

·

CVE-2026-100740

·

Published

2026-09-26

·

Updated

2026-09-28

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DIR-895L version A1 102b07
Description An out-of-bounds write can be triggered remotely via the L2TP Control Channel Parser component. The issue exists within the tunnel set params() function located in the tunnel.c file, where improper manipulation of data leads to memory corruption.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the L2TP Control Channel Parser component to minimize the risk of exploitation.

Exploit

RCE

Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-15578
CVE-2026-100740

Affected Products

Dir-895L