Impact
An off‑by‑one bounds error in the tunnel_set_params function of the L2TP Control Message Parser allows a remote attacker to supply a manipulated peer_hostname string, potentially corrupting memory and enabling arbitrary code execution. The vulnerability is rooted in arithmetic and buffer overflow weaknesses (CWE‑189, CWE‑193), which, when triggered, can compromise confidentiality, integrity, and availability of the affected device.
Affected Systems
The flaw affects D‑Link DIR‑605 routers running firmware version B1v202WWB03. No other vendors or products are listed in the CNA data.
Risk and Exploitability
The CVSS score of 9.2 reflects a high‑severity risk. EPSS score of 1% indicates a low but non‑zero exploitation probability, and the vulnerability is not currently in CISA KEV. The attack can be carried out remotely over L2TP, but the exploitation is considered difficult and requires sophisticated manipulation. Publicly available exploits have been documented, indicating that attackers may use this flaw to gain control of the target device.
OpenCVE Enrichment