Impact
A buffer overrun in the function tunnel_set_params of the L2TP Control Channel Parser allows an attacker to write data out of bounds, as indicated by CWE‑119 and CWE‑787. The flaw can be triggered by a specially crafted L2TP request and may lead to arbitrary code execution or a crash that can be leveraged for further compromise. The vulnerability is already publicly exploited and can be activated from outside the local network.
Affected Systems
The affected configuration is D‑Link DIR‑895L routers running firmware version A1_102b07. No other versions or models are explicitly listed, so all units with that firmware are considered vulnerable.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity and the exploit is known to be publicly available. Because the attack vector is remote, any device exposed to the Internet can be targeted. The EPSS score is not disclosed, and the issue is not yet listed in the CISA KEV catalog, but the presence of a public exploit already raises the likelihood of real‑world attacks. The vulnerability attacks the L2TP protocol normally used for VPN connections, so systems with active L2TP services are at the highest risk.
OpenCVE Enrichment