Remote Out-of-Bounds Write in D-Link DIR-895L L2TP Parser
A critical out-of-bounds write vulnerability (CVE-2026-100740) in the D-Link DIR-895L L2TP control channel parser allows remote attackers to potentially achieve code execution.
CVE search metadata
CVE search record: CVE-2026-100740. Severity: critical. CVSS: 9.9. KEV: no. Product: DIR-895L (A1_102b07). Brief: Remote Out-of-Bounds Write in D-Link DIR-895L L2TP Parser. Brief link: https://feed.craftedsignal.io/briefs/2026-09-dlink-l2tp-oob/
D-Link DIR-895L firmware version A1_102b07 contains a critical security vulnerability identified as CVE-2026-100740. The flaw resides within the L2TP Control Channel Parser, specifically inside the tunnel_set_params function located in tunnel.c. An attacker can trigger an out-of-bounds write via a crafted remote request. Because this is a memory corruption vulnerability within a networking component, successful exploitation could lead to arbitrary code execution or a denial-of-service condition for the affected router. Publicly available exploit material exists, increasing the risk of exploitation. Defenders should treat this as a high-priority risk for edge network devices.
Impact
The vulnerability carries a CVSS v3.1 base score of 9.9, reflecting its severity as a remote, unauthenticated code execution vector. Successful exploitation compromises the integrity and availability of the affected D-Link DIR-895L device, potentially allowing an attacker to intercept traffic, pivot into the local network, or render the device unusable.
Recommendation
- Immediately identify and isolate all D-Link DIR-895L (firmware A1_102b07) devices from the internet-facing edge of the network.
- Check the vendor support portal for official firmware patches addressing CVE-2026-100740 and apply them immediately upon release.
- If no patch is available, implement firewall rules to block unsolicited inbound L2TP traffic (typically UDP port 1701) directed at the router's WAN interface.
Immediate actions
Isolate affected D-Link DIR-895L routers from the public internet.
Mitigations
Block UDP port 1701 traffic on the WAN interface of the affected routers.
CVE-2026-100740