CVE-2026-86297 Details
Description
A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
An off-by-one vulnerability allowing an out-of-bounds write has been identified in the D-Link DIR-605 B1, specifically in version B1v202WWB03. This issue arises in the L2TP Control Message Parser, within the tunnel_set_params function of the file progs.gpl/pppd.alpha/l2tp/tunnel.c. The vulnerability can be exploited remotely, although such attacks are considered highly complex and difficult to execute.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 7, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://tzh00203.notion.site/D-Link-DIR-605-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a809ba163f988c15fc1b7 | [email protected] | |
| https://vuldb.com/cve/CVE-2026-86297 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/906299 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399459 | [email protected] | Content Wall |
| https://vuldb.com/vuln/399459/cti | [email protected] | Content Wall |
| https://www.dlink.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-189 | Numeric Errors | [email protected] |
| CWE-193 | Off-by-one Error | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| D-Link DIR-605 | B1v202WWB03 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 7, 2026 | New CVE Received | [email protected] |
Volerion