Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-100740: D-Link DIR-895L remote attacker can corrupt memory
CVE-2026-100740 · published 13 days ago
Summary
The D-Link DIR-895L router contains a flaw in its L2TP control channel code that lets an attacker send specially crafted data and write outside the intended memory area. This can cause the device to crash or be taken over, and the attack can be launched from anywhere on the Internet. Apply the latest firmware update from D‑Link as soon as possible to fix the problem.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dir-895l | A1_102b07 |
Original advisory text
D-Link DIR-895L L2TP Control Channel tunnel.c tunnel_set_params out-of-bounds write
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.6
High
Type
CWE-787Out-of-bounds Write
CWE-119Buffer Overflow
Timeline
Published27 Sep 2026
Updated7 Oct 2026
First seen27 Sep 2026
Track software like this
Free during beta