CVE-2026-100740Critical· 9.9▾ MidnightA vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 54.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-96891Critical· 9.8A vulnerability was identified in D-Link DIR-825 3.00b32
CVE-2026-86510Critical· 9.9A vulnerability has been found in D-Link DIR-822A A_101
CVE-2026-86509Critical· 9.6A flaw has been found in D-Link DIR-895L A1_102b07
CVE-2026-94089Critical· 10.0A vulnerability was determined in D-Link DIR-868L 2.01b05
CVE-2026-91003Critical· 9.1A flaw has been found in D-Link DI-8300 16.07
CVE-2026-91001Critical· 9.9A security flaw has been discovered in D-Link DI-8400 16.07