← Back to overview

A vulnerability was identified in D-Link DIR-605 B1v202WWB03 affecting the function tunnel_set_params in the L2TP Control Message Parser component. The flaw resides in the file progs.gpl/pppd.alpha/l2tp/tunnel.c and is triggered by manipulation of the peer_hostname argument, leading to an off-by-one error. The attack can be performed remotely, though it is assessed as highly complex and difficult to exploit. A public exploit is available, increasing the risk of exploitation in the wild. The vulnerability is classified as an out-of-bounds write condition. It impacts the L2TP tunneling functionality of the affected router firmware. No patch details are mentioned in the article. The availability of a public exploit elevates the overall risk level. Organizations using the affected D-Link hardware should monitor for updates from D-Link.

Affected products

  • D-Link DIR-605 B1v202WWB03

Related CVE's

  • CVE-2026-86297

Categories

  • Mobile & IoT
  • Network Infrastructure