CRITICAL
D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write
Published Sep 24, 2026
9.3
CRITICALCVSS 4.0
EPSS 0.65%
Description
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely.
Affected products
-
Affected
- 3.00b32
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85781 Advisory
- https://tzh00203.notion.site/D-Link-DIR-825-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a80458ffec58b62096940 related
- https://vuldb.com/cve/CVE-2026-96891 third-party-advisory
- https://vuldb.com/submit/906301 third-party-advisory
- https://vuldb.com/vuln/409134 vdb-entrytechnical-description
- https://vuldb.com/vuln/409134/cti signaturepermissions-required
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85781 | Advisory | |
| https://tzh00203.notion.site/D-Link-DIR-825-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a80458ffec58b62096940 | related | |
| https://vuldb.com/cve/CVE-2026-96891 | third-party-advisory | |
| https://vuldb.com/submit/906301 | third-party-advisory | |
| https://vuldb.com/vuln/409134 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/409134/cti | signaturepermissions-required | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 24, 2026
Updated Sep 24, 2026
Reserved Sep 23, 2026
Link CVE-2026-96891
CISA Vulnrichment
Updated Sep 24, 2026
Red Hat
No data
GitHub
No data