OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-100740

CRITICAL · CVSS 9.9 EPSS 0.45% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the D-Link DIR-895L router, specifically in the L2TP Control Channel Parser's tunnel_set_params function, which allows for an out-of-bounds write. This flaw can be exploited remotely, potentially compromising the device's integrity and leading to unauthorized access or control. Organizations using this router model should prioritize immediate patching or mitigation efforts to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-100740
Severity
CRITICAL
CVSS
9.9
EPSS
0.45%

Original NVD Description

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.