CVE-2026-86297
Received Received - Intake

Buffer Overflow in D-Link DIR-605 B1v202WWB03 L2TP Parser

Vulnerability report for CVE-2026-86297, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: VulDB

Description

A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostnameΒ  leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
d-link dir-605 b1v202wwb03

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-193 A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.
CWE-189

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an off-by-one error in the L2TP Control Message Parser of D-Link DIR-605 B1v202WWB03 firmware. It occurs in the tunnel_set_params function when handling the peer_hostname argument, potentially allowing remote attackers to exploit memory corruption. The exploit is publicly available but considered difficult to execute.

Impact Analysis

If exploited, this vulnerability could allow remote attackers to execute arbitrary code or cause denial-of-service conditions on affected D-Link DIR-605 devices. This may lead to unauthorized access, data theft, or disruption of network services.

Compliance Impact

The vulnerability involves an off-by-one error in the L2TP Control Message Parser, potentially allowing remote attacks. While it could lead to unauthorized access or data breaches, the provided CVE details do not specify direct impacts on GDPR or HIPAA compliance. However, such vulnerabilities often risk exposing sensitive data, which may violate these regulations if exploited.

Mitigation Strategies

Immediate mitigation steps include updating the D-Link DIR-605 firmware to the latest version if available, disabling L2TP services if not in use, and monitoring network traffic for unusual activity. Since the exploit is publicly available, prioritize patching or isolating affected devices.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86297. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart