D-Link DIR-825 3.00b32 rp-l2tp tunnel_set_params OOB Write via peer_hostname
CVE-2026-96891 Published on September 24, 2026

D-Link DIR-825 rp-l2tp tunnel.c tunnel_set_params out-of-bounds write
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

What is a Memory Corruption Vulnerability?

The software writes data past the end, or before the beginning, of the intended buffer. Typically, this can result in corruption of data, a crash, or code execution. The software may modify an index or perform pointer arithmetic that references a memory location that is outside of the boundaries of the buffer. A subsequent write operation then produces undefined or unexpected results.

CVE-2026-96891 has been classified to as a Memory Corruption vulnerability or weakness.

What is a Buffer Overflow Vulnerability?

The software performs operations on a memory buffer, but it can read from or write to a memory location that is outside of the intended boundary of the buffer.

CVE-2026-96891 has been classified to as a Buffer Overflow vulnerability or weakness.


Products Associated with CVE-2026-96891

Want to know whenever a new CVE is published for D Link Dir 825? stack.watch will email you.

 

Affected Versions

D-Link DIR-825 Version 3.00b32 is affected by CVE-2026-96891