← Back to CVE List
Vulnerability Intelligence Report
D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write

CVE-2026-96891

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.

Memory Corruption No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-787 ↗Out-of-bounds Write
CWE-119 ↗Memory Corruption

Affected Products & Versions

Vendor Product Affected Versions
D-Link DIR-825 3.00b32 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Memory Corruption

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityVulDB · Researcher · Switzerland
Reserved2026-09-23T19:12:25
Published2026-09-24T03:00:11
Last Updated2026-09-24T03:00:11

LINK COPIED TO CLIPBOARD