
Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and optionally sends a lab-only UDP 1701 trigger.
Python 3 PoC for CVE-2026-100740 — D-Link DIR-895L firmware A1_102b07.
CVE-2026-100740 — Out-of-bounds write (CWE-787 / CWE-119) in tunnel_set_params() (tunnel.c), L2TP control channel parser. Host Name AVP length is clamped to 127 but the NUL terminator is written at peer_hostname[len+1] on a 128-byte buffer → one-byte (and adjacent) memory corruption. Attack is remote over UDP 1701 when the device participates in L2TP (often WAN client to ISP L2TP server; malicious upstream/spoofed peer). Affected: DIR-895L A1_102b07 only (per VulDB). Public exploit referenced; no vendor fix listed in NVD at publication.
Research: Notion — DIR-895L L2TP Host Name AVP (same bug class as DIR-822A write-up).
PoC page: https://pocbit.org/pocs/cve-2026-100740
Catalog: https://pocbit.org/pocs/
| Vendor / model | D-Link DIR-895L |
| Firmware | A1_102b07 |
| Component | L2TP control parser / tunnel.c |
| Vector | Crafted Host Name AVP (len 127) |
| Port | UDP 1701 |
| CVSS 4.0 | VulDB PR:L, network, high impact |
This PoC fingerprints the router (HTTP), checks UDP 1701, optionally sends a lab-only SCCRQ trigger (--oob-send). It does not ship a full RCE chain.
pip install -r requirements.txt
python poc.py -u 192.168.0.1 --mode check
python poc.py -u 192.168.0.1 --mode check --l2tp-probe
python poc.py -u 192.168.0.1 --mode exploit --oob-send
python poc.py --list targets.example.txt --mode check -j 20
CVE-2026-100740 PoC: D-Link DIR-895L A1_102b07 L2TP Host Name AVP out-of-bounds write (tunnel_set_params). Detects device, UDP 1701, optional OOB trigger packet. PoCbit
CVE-2026-100740: DIR-895L A1_102b07 L2TP parser’da Host Name AVP ile OOB write; uzaktan UDP 1701. PoC: tespit + lab’de --oob-send.
Authorized testing only. --oob-send may crash the router.