Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-96891: D-Link DIR-825 remote write error in L2TP tunnel
CVE-2026-96891 · published 16 days ago
Summary
The D-Link DIR-825 router version 3.00b32 has a coding mistake in its L2TP tunnel component that can write data outside its intended memory area when a specially crafted host name is sent. An attacker on the network could exploit this to disrupt the router or potentially take control. Update the router firmware to the latest version or apply the vendor's security patch to fix the issue.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dir-825 | 3.00b32 |
Original advisory text
D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely.
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-119Buffer Overflow
CWE-787Out-of-bounds Write
Timeline
Published24 Sep 2026
Updated7 Oct 2026
First seen24 Sep 2026
Track software like this
Free during beta