CVE -2026-100740 is a critical vulnerability in the D-Link DIR-895Lthat could allow a remote attacker to cause an out-of-memory write. The issue is found in L2TP mode and is of particular concern because the model has been discontinued.

The CVE Feed was published on September 27, 2026 and describes the bug as an out-of-bounds write. The attack can be launched over a network, and the related report notes that an exploit is available that could be used.
CVE -2026-100740 does not affect the router's management environment, but rather the way it processes specific L2TP requests. This is important for organizations using older devices for remote access, as a network-level vulnerability can simultaneously impact connectivity and isolation of internal systems.
The available information does not document active exploitation in real-world attacks or provide a specific code sample. However, the public exploit report and the lack of a modern support cycle create a combination that requires immediate inventory, rather than waiting until a malfunction occurs.
See also: D-Link DIR-822A: Critical vulnerabilities threaten routers
What does CVE-2026-100740 mean for the D-Link DIR-895L?
The issue concerns the tunnel.c file, and specifically the tunnel_set_params function , which belongs to the L2TP Control Channel parser. Simply put, specially crafted data can cause the software to write beyond the bounds of the allocated memory. Such an error can cause a crash, corrupt execution flow, or, under certain conditions, code execution.
The database gives the vulnerability a high CVSS score of 4.0, while the entry shows an even higher severity in older metrics. The difference does not change the practical conclusion: a router located at the edge of an organization or home is a critical crossing point and should not be treated as a simple network device.

CVE -2026-100740 affects the D-Link DIR-895L firmware version A1_102b07 . The attack requires privileges at the level described in the assessment, but the ability to remotely initiate the process raises concerns for any network where L2TP is active or accessible. There is no indication that the vulnerability has been added to the CISA KEV list.
The assessment should not be read as an indication that every device on the internet is automatically vulnerable. Administrators need to confirm whether they are using a D-Link DIR-895L, the firmware version, and active services. At the same time, the absence of a confirmed attack does not reduce the need to restrict access, especially when the equipment is used in small offices or branch offices.
D-Link has marked the model as unsupported
The issue isn't just technical. In security update SAP10299, D-Link says the DIR-895L/R series has reached end of life and end of service. The company notes that firmware development has stopped and recommends that the devices be retired and replaced.
The same page lists other issues with the D-Link DIR-895L, including vulnerabilities in the DHCP daemon and older overflow bugs. This means that even if a temporary fix is released for the new vulnerability, administrators should consider the overall risk of a product that no longer receives regular updates.
See also: ZBT Routers: Two hidden implants give hackers root access

What should administrators do?
IT teams should first identify if a DIR-895L exists in their environment and confirm the firmware version. Until there is clear guidance from the manufacturer, the SecNews technical team recommends disabling L2TP where not necessary, limiting the device's access to trusted networks, and preventing it from being exposed to the internet.
Network segmentation, firewall rules, and monitoring for unusual traffic to router services can temporarily reduce exposure, but they are no substitute for upgrading. Since D-Link considers the model obsolete, the safest solution is to upgrade to supported equipment with active updates.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: D-Link DWR-M961: 18 vulnerabilities allow root commands
The publication of CVE-2026-100740 is a reminder that network equipment remains part of the attack surface, even when it shows no symptoms of compromise. For a D-Link DIR-895L, the lack of active support makes replacement more reliable than waiting for a patch that may never be released.
