<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:o:dlink:dir-605_firmware:b1v202wwb03:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3odlinkdir-605_firmwareb1v202wwb03/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 12:53:06 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3odlinkdir-605_firmwareb1v202wwb03/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Off-by-One Vulnerability in D-Link DIR-605 L2TP Parser</title><link>https://feed.craftedsignal.io/briefs/2026-09-dlink-l2tp-off-by-one/</link><pubDate>Mon, 07 Sep 2026 12:53:06 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-dlink-l2tp-off-by-one/</guid><description>An off-by-one vulnerability in the L2TP Control Message Parser of D-Link DIR-605 routers allows remote attackers to trigger memory corruption via a malicious peer_hostname argument.</description><content:encoded><![CDATA[<p>A critical security flaw (CVE-2026-86297) has been identified in the D-Link DIR-605 router, specifically within the B1v202WWB03 firmware version. The vulnerability resides in the L2TP (Layer 2 Tunneling Protocol) Control Message Parser component, specifically within the <code>tunnel_set_params</code> function located in the file <code>progs.gpl/pppd.alpha/l2tp/tunnel.c</code>. An attacker can remotely exploit this by sending a crafted L2TP control message containing a malformed <code>peer_hostname</code> argument. This manipulation triggers an off-by-one error, potentially leading to memory corruption or instability in the device's control process. While the exploitation process is classified as highly complex and difficult to execute successfully, functional exploit code is publicly available, increasing the risk to exposed devices. Defenders should prioritize isolating affected D-Link devices or ensuring they are not reachable from untrusted networks, as L2TP is a common target for remote service exploitation.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows a remote, unauthenticated attacker to cause a denial-of-service condition or potentially execute arbitrary code on the affected D-Link router. Given that the device is a consumer-grade router, compromise could allow an attacker to intercept local network traffic, bypass authentication, or use the device as a pivot point for further lateral movement within the victim's internal network.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the decommissioning or network segmentation of D-Link DIR-605 routers running firmware version B1v202WWB03. Since no specific patch is documented, implement edge filtering to block unsolicited L2TP (UDP port 1701) traffic originating from the internet to internal assets. Monitor network telemetry for anomalous L2TP control packets that exhibit unusually long or malformed hostname fields.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>