---
id: CVE-2026-86297
title: A vulnerability was identified in D-Link DIR-605 B1v202WWB03
summary: >-
  A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue
  affects the function tunnel_set_params of the file
  progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message
  Parser. Such manipulation of the argumen…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-189
  - CWE-193
vendor: D-Link
product: DIR-605
affected:
  - DIR-605 B1v202WWB03
published: '2026-09-07'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T15:17:16.647'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86297'
references:
  - url: >-
      https://tzh00203.notion.site/D-Link-DIR-605-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a809ba163f988c15fc1b7
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86297'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/906299'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399459'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399459/cti'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-09T14:22:33.709847Z'
epss: 0.01124
epssPercentile: 0.64859
ingestedAt: '2026-09-08T15:33:26.976Z'
---

## Overview

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
