CVE-2026-86297High· 8.1▾ MidnightPoC availableA vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argumen…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 44.6 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
1.0%
Last analysed / modified upstream
Exploit / PoC code exists
A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-94089Critical· 10.0A vulnerability was determined in D-Link DIR-868L 2.01b05
CVE-2026-94036High· 8.8A security flaw has been discovered in D-Link DIR-X1860 and DIR-X1860Z up to 1.0.2.220120.165402
CVE-2026-93958Critical· 9.1A vulnerability was found in D-Link R95 BE9500_1.00.16
CVE-2026-91003Critical· 9.1A flaw has been found in D-Link DI-8300 16.07
CVE-2026-91001Critical· 9.9A security flaw has been discovered in D-Link DI-8400 16.07
CVE-2026-90881Medium· 5.3A weakness has been identified in D-Link DIR-882 up to 20260814