OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-96891 (CVSS 9.3)

NVD · officialPublished Sep 24, 2026Risk 50/100EPSS 0.7%

A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname  leads to out-of-bounds write. The attack may be initiated remotely.

CVSS
9.3
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source