Skip to content
Threat Feed
critical advisory

Remote Out-of-Bounds Write in D-Link DIR-895L L2TP Parser

A critical out-of-bounds write vulnerability (CVE-2026-100740) in the D-Link DIR-895L L2TP control channel parser allows remote attackers to potentially achieve code execution.

CVE search metadata

CVE search record: CVE-2026-100740. Severity: critical. CVSS: 9.9. KEV: no. Product: DIR-895L (A1_102b07). Brief: Remote Out-of-Bounds Write in D-Link DIR-895L L2TP Parser. Brief link: https://feed.craftedsignal.io/briefs/2026-09-dlink-l2tp-oob/

D-Link DIR-895L firmware version A1_102b07 contains a critical security vulnerability identified as CVE-2026-100740. The flaw resides within the L2TP Control Channel Parser, specifically inside the tunnel_set_params function located in tunnel.c. An attacker can trigger an out-of-bounds write via a crafted remote request. Because this is a memory corruption vulnerability within a networking component, successful exploitation could lead to arbitrary code execution or a denial-of-service condition for the affected router. Publicly available exploit material exists, increasing the risk of exploitation. Defenders should treat this as a high-priority risk for edge network devices.

Impact

The vulnerability carries a CVSS v3.1 base score of 9.9, reflecting its severity as a remote, unauthenticated code execution vector. Successful exploitation compromises the integrity and availability of the affected D-Link DIR-895L device, potentially allowing an attacker to intercept traffic, pivot into the local network, or render the device unusable.

Recommendation

  • Immediately identify and isolate all D-Link DIR-895L (firmware A1_102b07) devices from the internet-facing edge of the network.
  • Check the vendor support portal for official firmware patches addressing CVE-2026-100740 and apply them immediately upon release.
  • If no patch is available, implement firewall rules to block unsolicited inbound L2TP traffic (typically UDP port 1701) directed at the router's WAN interface.

Immediate actions

Isolate affected D-Link DIR-895L routers from the public internet.

Network Operations 24h

Mitigations

Block UDP port 1701 traffic on the WAN interface of the affected routers.

immediate Network Operations

CVE-2026-100740