← Back to search

CVE-2026-100740

9.9 CRITICAL

Published 2026-09-27 · Updated 2026-09-28

AI risk analysis

Summary
The flaw allows out-of-bounds write in the L2TP Control Channel Parser, enabling remote code execution.
Exploitability
Exploitation is relatively straightforward with a public exploit available.
Blast radius
If exploited, it could lead to full remote code execution and control of the device.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the fixed version 102b07 or later.
rceremote-code-executionl2tpout-of-bounds-write

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-119, CWE-787

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.