CVE-2026-100740

LOWCVSS 8.6 · HIGH

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Parser. Performing a manipulation results in out-of-bounds write. The attack may be initiated remotely. The exploit is now public and may be used.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 4 mentions on most recent observed day (2026-09-27)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-09-26: 1Mentions · 2026-09-27: 409-2609-27
Referenced assets5 URLs
Full discourse5 posts
  • mürrez@murrezsec

    New PoC live — CVE-2026-100740 🔍 D-Link DIR-895L (A1_102b07): L2TP Host Name AVP out-of-bounds write (UDP 1701). Fingerprint + lab trigger in repo. 🔗 https://pocbit.org/pocs/cve-2026-100740 #CVE #IoT #CyberSecurity #RedTeam #VulnerabilityResearch

    1002069
    607 followersView on X
  • ThreatAft@ThreatAft

    🚨 D-LINK DIR-895L CVE-2026-100740 — CVSS 9.9 L2TP Control Channel Parser out-of-bounds write. Memory corruption → RCE. Isolate or replace NOW. → https://threataft.com/articles/d-link-dir-895l-cve-2026-100740-l2tp-out-of-bounds-write #DLink #CVE #RCE #PatchNow #CyberSecurity #ThreatIntel

    0000025
    44 followersView on X
  • CVE@CVEnew

    CVE-2026-100740 A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel.c of the component L2TP Control Channel Par… https://www.cve.org/CVERecord?id=CVE-2026-100740

    00000451
    58.1K followersView on X
  • SecNews@SecNews_GR

    D-Link DIR-895L: Κρίσιμη ευπάθεια CVE-2026-100740 χωρίς υποστήριξη https://www.secnews.gr/736242/d-link-dir-895l-cve-2026-100740/?fsp_sid=15113

    00000151
    7.0K followersView on X
  • VulDB 🛡@vuldb

    The severity is increased for this new vulnerability affecting D-Link DIR-895L (CVE-2026-100740) https://vuldb.com/vuln/410614

    0000095
    2.3K followersView on X

Explore more