CVE-2026-96891

Summary

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.

Affected Software

VendorProductVersion RangeStatus
D-LinkDIR-8253.00b32affected

Weaknesses

  • CWE-787: Out-of-bounds Write
  • CWE-119: Memory Corruption

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References