rootpwn

critical · CVSS v3 9.9 · CVSS v4 9.4 · EPSS 0.00453

CVE-2026-100740

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel…

Description

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

Scores

Severity
critical
CVSS v2
9
CVSS v3
9.9
CVSS v4
9.4
EPSS
0.00453

← All CVEs