CVE-2026-86297
8.1D-Link · DIR-605
An off-by-one vulnerability in the L2TP Control Message Parser of D-Link DIR-605 allows remote attackers to trigger memory corruption via the peer_hostname argument.
Executive summary
A remote, unauthenticated off-by-one vulnerability in the D-Link DIR-605 L2TP parser poses a critical risk of memory corruption and potential system compromise.
Vulnerability
This vulnerability occurs within the tunnel_set_params function of the L2TP Control Message Parser, where an off-by-one error can be triggered by manipulating the peer_hostname argument. The flaw is remotely exploitable by an unauthenticated attacker, though the complexity of the exploit is high.
Business impact
The vulnerability carries a CVSS score of 8.1, indicating a high severity level. Successful exploitation could lead to full system compromise, resulting in unauthorized access to network traffic, potential data exfiltration, or complete device downtime, causing significant operational disruption.
Remediation
Immediate Action: There is currently no official patch available; users should restrict L2TP access to trusted internal sources or disable the L2TP feature entirely until the vendor releases a firmware update.
Proactive Monitoring: Monitor device access logs and network traffic for unusual L2TP control messages or repeated connection attempts that deviate from established baseline behaviors.
Compensating Controls: Deploy a network-level firewall or Intrusion Prevention System (IPS) to filter malformed L2TP packets before they reach the vulnerable device.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as detailed in the researcher write-up referenced by the CVE record.
Analyst recommendation
Given the potential for remote code execution and the availability of public technical details, this vulnerability presents a significant risk to affected D-Link infrastructure. IT administrators should prioritize isolating affected devices from the internet and applying firmware updates as soon as the manufacturer provides them.
More D-Link CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by tian (VulDB User), per the CVE Program record.
- VDB-399459 | D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one Vulnerability database entry
- VDB-399459 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-86297 | CVE Analysis and Report Third-party advisory
- Submit #906299 | D-Link DIR605 B1v202WWB03 B1v202WWB03 Out-of-bounds Write Third-party advisory
- Exploit / PoC
- dlink.com