Junglewise Threat Intelligence

CVE-2026-100740: D-Link DIR-895L out-of-bounds write in L2TP parser

CVE-2026-100740 · Severity: critical · CVSS 9.9 · Published 2026-09-27

Technologies: D-Link DIR-895L. Vendors: D-Link.

Executive brief

The D-Link DIR-895L router contains an out-of-bounds write vulnerability in its L2TP (Layer 2 Tunneling Protocol) parser that can be exploited remotely without authentication. An attacker can send specially crafted L2TP control channel packets to crash the router or potentially execute arbitrary code, disrupting network connectivity and creating a foothold for further compromise. The vulnerability has been publicly disclosed and may be actively exploited.

Technical details

The vulnerability exists in the tunnel_set_params function of tunnel.c in the L2TP Control Channel Parser component, allowing out-of-bounds write through improper handling of L2TP packets. The attack requires only network connectivity with no authentication or user interaction, and can result in denial of service or code execution depending on memory layout. A fix is assumed to be available through D-Link firmware updates.

Affected products

  • D-Link DIR-895L A1_102b07

Timeline

  • 2026-09-27: disclosed: Public disclosure of CVE-2026-100740

References

Related threats