🔐 CVE Alert

CVE-2026-86297

HIGH 8.1

D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.

CWE CWE-193 CWE-189
Vendor d-link
Product dir-605
Published Sep 7, 2026
Last Updated Sep 9, 2026
Stay Ahead of the Next One

Get instant alerts for d-link dir-605

Be the first to know when new high vulnerabilities affecting d-link dir-605 are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

D-Link / DIR-605
B1v202WWB03

References

NVD ↗ CVE.org ↗ EPSS Data ↗
vuldb.com: https://vuldb.com/vuln/399459 vuldb.com: https://vuldb.com/vuln/399459/cti vuldb.com: https://vuldb.com/cve/CVE-2026-86297 vuldb.com: https://vuldb.com/submit/906299 tzh00203.notion.site: https://tzh00203.notion.site/D-Link-DIR-605-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a809ba163f988c15fc1b7 dlink.com: https://www.dlink.com/

Credits

🔍 tian (VulDB User)