Skip to content
Threat Feed
high advisory

Remote Off-by-One Vulnerability in D-Link DIR-605 L2TP Parser

An off-by-one vulnerability in the L2TP Control Message Parser of D-Link DIR-605 routers allows remote attackers to trigger memory corruption via a malicious peer_hostname argument.

CVE search metadata

CVE search record: CVE-2026-86297. Severity: high. CVSS: 8.1. KEV: no. Product: DIR-605 (B1v202WWB03). Brief: Remote Off-by-One Vulnerability in D-Link DIR-605 L2TP Parser. Brief link: https://feed.craftedsignal.io/briefs/2026-09-dlink-l2tp-off-by-one/

A critical security flaw (CVE-2026-86297) has been identified in the D-Link DIR-605 router, specifically within the B1v202WWB03 firmware version. The vulnerability resides in the L2TP (Layer 2 Tunneling Protocol) Control Message Parser component, specifically within the tunnel_set_params function located in the file progs.gpl/pppd.alpha/l2tp/tunnel.c. An attacker can remotely exploit this by sending a crafted L2TP control message containing a malformed peer_hostname argument. This manipulation triggers an off-by-one error, potentially leading to memory corruption or instability in the device's control process. While the exploitation process is classified as highly complex and difficult to execute successfully, functional exploit code is publicly available, increasing the risk to exposed devices. Defenders should prioritize isolating affected D-Link devices or ensuring they are not reachable from untrusted networks, as L2TP is a common target for remote service exploitation.

Impact

Successful exploitation of this vulnerability allows a remote, unauthenticated attacker to cause a denial-of-service condition or potentially execute arbitrary code on the affected D-Link router. Given that the device is a consumer-grade router, compromise could allow an attacker to intercept local network traffic, bypass authentication, or use the device as a pivot point for further lateral movement within the victim's internal network.

Recommendation

Prioritize the decommissioning or network segmentation of D-Link DIR-605 routers running firmware version B1v202WWB03. Since no specific patch is documented, implement edge filtering to block unsolicited L2TP (UDP port 1701) traffic originating from the internet to internal assets. Monitor network telemetry for anomalous L2TP control packets that exhibit unusually long or malformed hostname fields.


Immediate actions

Block UDP port 1701 (L2TP) on internet-facing firewalls for affected D-Link devices.

IT Operations 24h

Mitigations

Isolate or replace D-Link DIR-605 (B1v202WWB03) units until a firmware patch is released.

immediate IT Operations

CVE-2026-86297