CVE-2026-86297

8.1

D-Link · DIR-605

An off-by-one vulnerability in the L2TP Control Message Parser of D-Link DIR-605 allows remote attackers to trigger memory corruption via the peer_hostname argument.

Executive summary

A remote, unauthenticated off-by-one vulnerability in the D-Link DIR-605 L2TP parser poses a critical risk of memory corruption and potential system compromise.

Vulnerability

This vulnerability occurs within the tunnel_set_params function of the L2TP Control Message Parser, where an off-by-one error can be triggered by manipulating the peer_hostname argument. The flaw is remotely exploitable by an unauthenticated attacker, though the complexity of the exploit is high.

Business impact

The vulnerability carries a CVSS score of 8.1, indicating a high severity level. Successful exploitation could lead to full system compromise, resulting in unauthorized access to network traffic, potential data exfiltration, or complete device downtime, causing significant operational disruption.

Remediation

Immediate Action: There is currently no official patch available; users should restrict L2TP access to trusted internal sources or disable the L2TP feature entirely until the vendor releases a firmware update.

Proactive Monitoring: Monitor device access logs and network traffic for unusual L2TP control messages or repeated connection attempts that deviate from established baseline behaviors.

Compensating Controls: Deploy a network-level firewall or Intrusion Prevention System (IPS) to filter malformed L2TP packets before they reach the vulnerable device.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the researcher write-up referenced by the CVE record.

Analyst recommendation

Given the potential for remote code execution and the availability of public technical details, this vulnerability presents a significant risk to affected D-Link infrastructure. IT administrators should prioritize isolating affected devices from the internet and applying firmware updates as soon as the manufacturer provides them.

More D-Link CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by tian (VulDB User), per the CVE Program record.