
New PoC live — CVE-2026-100740 🔍 D-Link DIR-895L (A1_102b07): L2TP Host Name AVP out-of-bounds write (UDP 1701). Fingerprint + lab trigger in repo. 🔗 https://pocbit.org/pocs/cve-2026-100740 #CVE #IoT #CyberSecurity #RedTeam #VulnerabilityResearch
Signal is active with 4 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
STABLE

New PoC live — CVE-2026-100740 🔍 D-Link DIR-895L (A1_102b07): L2TP Host Name AVP out-of-bounds write (UDP 1701). Fingerprint + lab trigger in repo. 🔗 https://pocbit.org/pocs/cve-2026-100740 #CVE #IoT #CyberSecurity #RedTeam #VulnerabilityResearch

🚨 D-LINK DIR-895L CVE-2026-100740 — CVSS 9.9 L2TP Control Channel Parser out-of-bounds write. Memory corruption → RCE. Isolate or replace NOW. → https://threataft.com/articles/d-link-dir-895l-cve-2026-100740-l2tp-out-of-bounds-write #DLink #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

CVE-2026-100740 A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Par… https://www.cve.org/CVERecord?id=CVE-2026-100740

D-Link DIR-895L: Κρίσιμη ευπάθεια CVE-2026-100740 χωρίς υποστήριξη https://www.secnews.gr/736242/d-link-dir-895l-cve-2026-100740/?fsp_sid=15113

The severity is increased for this new vulnerability affecting D-Link DIR-895L (CVE-2026-100740) https://vuldb.com/vuln/410614