A critical out-of-bounds write in the L2TP control-channel parser of D-Link DIR-895L firmware A1_102b07 enables a low-privileged remote attacker to send a crafted L2TP packet with manipulated Host Name AVP data, corrupt memory in tunnel_set_params, and potentially execute code on the router. Tracked as CVE-2026-100740, the flaw is rated CVSS 9.9 and has a public proof of concept; no confirmed patch, mitigation, or CISA Known Exploited Vulnerabilities listing was reported.
A closely related flaw, CVE-2026-96891, affects the rp-l2tp implementation in D-Link DIR-825 firmware 3.00b32, where crafted peer_hostname input can trigger memory corruption and potentially cause denial of service or code execution. The DIR-825 is end of life with no listed fixed firmware, while DIR-895L operators should disable L2TP where possible, remove affected routers from Internet exposure, isolate them, and prioritize replacement; no confirmed in-the-wild exploitation was reported for either issue.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
cna@vuldb.com received the CVE entry for an out-of-bounds write in the D-Link DIR-895L A1_102b07 L2TP Control Channel Parser. The issue affects tunnel_set_params in tunnel.c, and the record states that a public exploit is available.
The CVE record for CVE-2026-96891 was published. The affected DIR-825 hardware is end-of-life, and no fixed firmware was listed.
A critical out-of-bounds write vulnerability in the rp-l2tp component's tunnel_set_params function was publicly disclosed affecting D-Link DIR-825 firmware 3.00b32. Crafted peer_hostname input can cause memory corruption, potentially resulting in denial of service or code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcethreataft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.