Executive brief
The D-Link DIR-605 wireless router contains a buffer handling flaw in its L2TP (Layer 2 Tunneling Protocol) implementation that allows remote attackers to write one byte beyond the intended buffer boundary. Exploitation is complex and requires crafted network packets, but successful attacks could lead to arbitrary code execution or denial of service, compromising the router's operation and potentially exposing the home or small-office network it protects.
Technical details
An off-by-one vulnerability exists in the tunnel_set_params function within the L2TP Control Message Parser component of D-Link DIR-605 B1v202WWB03. The flaw is triggered via improper handling of the peer_hostname argument, allowing an attacker to write one byte beyond the allocated buffer boundary. The attack is network-accessible and requires no authentication, but exploitation is assessed as difficult due to the complexity of crafting a valid L2TP control message. A public proof-of-concept exploit is available. Successful exploitation could result in memory corruption leading to code execution or device crash.
Affected products
- D-Link DIR-605 B1v202WWB03
Timeline
- 2026-09-07: disclosed