CVE-2026-96891

9.8

D-Link · DIR-825

D-Link DIR-825 is vulnerable to an out-of-bounds write via the peer_hostname argument in the rp-l2tp component, allowing remote unauthenticated attackers to potentially corrupt system memory.

Executive summary

A critical out-of-bounds write vulnerability in D-Link DIR-825 firmware exposes the device to remote memory corruption and potential system compromise.

Vulnerability

This vulnerability resides in the tunnel_set_params function within the rp-l2tp component, where improper handling of the peer_hostname argument leads to an out-of-bounds memory write. The attack is remotely exploitable without requiring authentication (AV:N/AC:L/AT:N/PR:N).

Business impact

The CVSS score of 9.8 reflects the high potential for full system compromise, including the possibility of remote code execution or persistent denial of service. Such an outcome could lead to unauthorized network access, interception of traffic, or complete loss of router availability, presenting a significant risk to organizational operations and data integrity.

Remediation

Immediate Action: Contact D-Link support or monitor the official D-Link security advisory page for the release of a firmware patch addressing this memory corruption flaw.

Proactive Monitoring: Review device logs for unusual L2TP tunnel connection attempts or unexpected system reboots that may indicate exploitation attempts.

Compensating Controls: If a patch is unavailable, restrict management access to the device from untrusted networks and disable L2TP functionality if it is not strictly required for business operations.

Exploitation status

Public Exploit Available: Yes, a published PoC exists, attributed to the research write-up referenced in the vulnerability disclosure.

Analyst recommendation

Given the critical nature of this vulnerability and its remote, unauthenticated attack vector, administrators must treat this as a high-priority risk. Immediately evaluate the necessity of the L2TP feature and implement network-level access controls to isolate affected devices until an official firmware update is verified and deployed.

More D-Link CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by tian (VulDB User), per the CVE Program record.