Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used. | |
| Title | D-Link DIR-605 L2TP Control Message tunnel.c tunnel_set_params off-by-one | |
| First Time appeared |
D-link
D-link dir-605 |
|
| Weaknesses | CWE-189 CWE-193 |
|
| CPEs | cpe:2.3:h:d-link:dir-605:*:*:*:*:*:*:*:* | |
| Vendors & Products |
D-link
D-link dir-605 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-07T10:45:26.431Z
Reserved: 2026-09-06T16:18:00.386Z
Link: CVE-2026-86297
No data.
Status : Received
Published: 2026-09-07T11:17:39.730
Modified: 2026-09-07T11:17:39.730
Link: CVE-2026-86297
No data.
OpenCVE Enrichment
No data.
