ZeroHour

CVE-2026-86297

large

Remote off-by-one in D-Link DIR-605 L2TP Control Message Parser

CVSS 4.0
8.2 high
EPSS
1%p62
Published
()
Modified
AI analysis

CVE-2026-86297 is an off-by-one memory-handling flaw in the tunnel_set_params function of the L2TP Control Message Parser (file progs.gpl/pppd.alpha/l2tp/tunnel.c) in D-Link DIR-605 firmware build B1v202WWB03. A remote attacker triggers it by sending a crafted L2TP control message whose peer_hostname argument is handled one element past the intended boundary, causing memory corruption on the device. Per the CVSS 4.0 scoring, successful exploitation can have high impact on the router's confidentiality, integrity, and availability (for example a crash or potential code execution), although the attack is described as highly complex and difficult to execute. Operators of D-Link DIR-605 B1 routers running the named firmware are affected, particularly where L2TP is in use or passed through. The advisory notes the exploit is publicly available and might be used, but no confirmed in-the-wild exploitation is documented (1% EPSS over 30 days, not in CISA KEV).

What to do: Inventory for DIR-605 routers running the B1v202WWB03 build and check whether L2TP is enabled; if L2TP is not required, disable it or restrict WAN exposure of L2TP control traffic. Because this model is end-of-life, check D-Link's support site for any updated firmware or plan replacement, and monitor for exploitation activity given that a public exploit exists.

Affected
D-Link DIR-605B1v202WWB03 (the only build named in the advisory; other hardware/firmware revisions are unconfirmed)
Estimated exposure
large≈10,000–100,000 units still in service worldwide (order-of-magnitude estimate; exact install base unknown) — The DIR-605 was a mass-market consumer router sold in large volumes years ago and has since reached end-of-life, so surviving deployments are plausibly in the tens of thousands, with effective exposure likely lower because exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.

Weakness
CWE-189, CWE-193
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.