Impact
The vulnerability occurs in the L2TP Control Message Parser function tunnel_set_params in D-Link DIR-822A firmware A_101. An attacker can manipulate input data to cause an out-of-bounds write, which may lead to arbitrary memory corruption. The flaw is a classic buffer underrun/overrun issue (CWE-119 and CWE-787).
Affected Systems
Devices running the D-Link DIR-822A router with firmware version A_101 are affected. No other firmware releases are currently known to be impacted.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity, and the vulnerability can be exploited remotely via the L2TP service. Although no EPSS score is available and the issue is not listed in the CISA KEV catalog, the public disclosure of the exploit and the remote nature of the attack vector increase the likelihood of real-world exploitation.
OpenCVE Enrichment