{"id":"CVE-2026-100740","title":"A vulnerability was detected in D-Link DIR-895L A1_102b07","summary":"A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack…","severity":"critical","cvss":9.9,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-119","CWE-787"],"vendor":"D-Link","product":"DIR-895L","affected":["DIR-895L A1_102b07"],"published":"2026-09-27","updated":"2026-09-27","sourceUpdated":"2026-09-27T01:17:17.810","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-100740","references":[{"url":"https://tzh00203.notion.site/D-Link-DIR-895L-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a8061b139cacc39d58fff","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-100740","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/906303","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410614","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/410614/cti","label":"cna@vuldb.com"},{"url":"https://www.dlink.com/","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-27T01:41:06.655Z","slug":"CVE-2026-100740","body":"## Overview\n\nA vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":54.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}