CVE-2026-96891
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component r
CVSS
9.8
Crítico
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 24 sept 2026 · Última mod.: 24 sept 2026 · CWE-119 · CWE-787
Sin historial EPSS suficiente todavía.
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely.
- tzh00203.notion.sitehttps://tzh00203.notion.site/D-Link-DIR-825-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a80458ffec58b62096940
- vuldb.comhttps://vuldb.com/cve/CVE-2026-96891
- vuldb.comhttps://vuldb.com/submit/906301
- vuldb.comhttps://vuldb.com/vuln/409134
- vuldb.comhttps://vuldb.com/vuln/409134/cti
- www.dlink.comhttps://www.dlink.com/
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-966766.3 MED—
———A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The impacted element is the function get_alias_name of the component uhttpd. Such manipulation leads to stack-based buffer overflow. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.11hCVE-2026-888396.7 MED—
——0BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of heap pointers.14hCVE-2026-888327.3 ALT—
——0BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow when processing crafted filesystem images.6hCVE-2026-918157.8 ALT8.4%
——3Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.17hCVE-2026-918117.8 ALT6.8%
——2A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes. Successful exploitation could result in memory corruption and an application crash.17hCVE-2026-918047.8 ALT6.8%
——2A heap-based out-of-bounds write vulnerability exists in Foxit PDF Editor/Reader’s rendering of Circle annotations with malformed Cloudy appearance streams in specially crafted PDF files. Insufficient validation of the appearance geometry can result in memory corruption and application crashes.17h