CVE-2026-100740: D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write
A vulnerability was detected in D-Link DIR-895L A1102b07. Impacted is the function tunnelsetparams of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access and interaction conditions does the CVSS vector indicate?
The vector indicates network-based exploitation with low attack complexity and no user interaction. It also indicates that the attacker needs low-level privileges; the provided data does not specify what account or privilege level satisfies this requirement.
Is exploit code available?
Yes. The provided data states that the exploit is public and may be used.
Which firmware version is specifically identified as affected?
The affected product information specifically identifies D-Link DIR-895L firmware A1_102b07. The data does not establish whether other firmware versions are affected.