{"id":"CVE-2026-96891","title":"A vulnerability was identified in D-Link DIR-825 3.00b32","summary":"A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack …","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-119","CWE-787"],"vendor":"D-Link","product":"DIR-825","affected":["DIR-825 3.00b32"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T03:16:58.950","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-96891","references":[{"url":"https://tzh00203.notion.site/D-Link-DIR-825-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a80458ffec58b62096940","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-96891","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/906301","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/409134","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/409134/cti","label":"cna@vuldb.com"},{"url":"https://www.dlink.com/","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-24T03:37:24.186Z","slug":"CVE-2026-96891","body":"## Overview\n\nA vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":53.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}