Description
A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
Published: 2026-09-07
Score: 9.2 Critical
EPSS: 1.1% Low
KEV: No
Impact: Remote code execution
Action: Immediate Patch
AI Analysis

Impact

An off‑by‑one bounds error in the tunnel_set_params function of the L2TP Control Message Parser allows a remote attacker to supply a manipulated peer_hostname string, potentially corrupting memory and enabling arbitrary code execution. The vulnerability is rooted in arithmetic and buffer overflow weaknesses (CWE‑189, CWE‑193), which, when triggered, can compromise confidentiality, integrity, and availability of the affected device.

Affected Systems

The flaw affects D‑Link DIR‑605 routers running firmware version B1v202WWB03. No other vendors or products are listed in the CNA data.

Risk and Exploitability

The CVSS score of 9.2 reflects a high‑severity risk. EPSS score of 1% indicates a low but non‑zero exploitation probability, and the vulnerability is not currently in CISA KEV. The attack can be carried out remotely over L2TP, but the exploitation is considered difficult and requires sophisticated manipulation. Publicly available exploits have been documented, indicating that attackers may use this flaw to gain control of the target device.

Generated by OpenCVE AI on September 8, 2026 at 15:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain the latest firmware for the D‑Link DIR‑605 from the vendor and apply the update to fix the L2TP control message parser error.
  • If L2TP functionality is not required, disable it entirely in the router’s configuration to eliminate the attack surface.
  • Configure the network perimeter or the device’s firewall to block inbound UDP traffic on port 1701 (L2TP) from untrusted networks.
  • As a temporary measure, restrict L2TP client connections to known, trusted hosts or apply a packet filter that drops malformed L2TP requests containing unusually long peer_hostname values.

Generated by OpenCVE AI on September 8, 2026 at 15:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 09 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 11:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
Title D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one
First Time appeared D-link
D-link dir-605
Weaknesses CWE-189
CWE-193
CPEs cpe:2.3:h:d-link:dir-605:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dir-605
References
Metrics cvssV2_0

{'score': 7.6, 'vector': 'AV:N/AC:H/Au:N/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 8.1, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-09T14:22:51.103Z

Reserved: 2026-09-06T16:18:00.386Z

Link: CVE-2026-86297

cve-icon Vulnrichment

Updated: 2026-09-09T14:22:41.436Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T11:17:39.730

Modified: 2026-09-09T15:17:16.647

Link: CVE-2026-86297

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T15:30:18Z

Weaknesses