Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-100740 — Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and optionally sends a lab-only UDP 1701 trigger. | Kitploit
Tools/GitHubGitHub/murrez/cve-2026-100740
Embedded Systems SecurityIoT SecurityVulnerability AnalysisExploitationInformation GatheringNetwork SecurityPenetration TestingHardware & IoT SecurityFirmware Analysis
GitHubmurrez/cve-2026-100740

CVE-2026-100740

Python PoC for CVE-2026-100740, an L2TP Host Name AVP out-of-bounds write in D-Link DIR-895L A1_102b07 tunnel_set_params. Fingerprints the device and optionally sends a lab-only UDP 1701 trigger.

116 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-100740 — D-Link DIR-895L L2TP OOB Write

Python 3 PoC for CVE-2026-100740 — D-Link DIR-895L firmware A1_102b07.

Description (PoCbit / GitHub)

CVE-2026-100740 — Out-of-bounds write (CWE-787 / CWE-119) in tunnel_set_params() (tunnel.c), L2TP control channel parser. Host Name AVP length is clamped to 127 but the NUL terminator is written at peer_hostname[len+1] on a 128-byte buffer → one-byte (and adjacent) memory corruption. Attack is remote over UDP 1701 when the device participates in L2TP (often WAN client to ISP L2TP server; malicious upstream/spoofed peer). Affected: DIR-895L A1_102b07 only (per VulDB). Public exploit referenced; no vendor fix listed in NVD at publication.

Research: Notion — DIR-895L L2TP Host Name AVP (same bug class as DIR-822A write-up).

PoC page: https://pocbit.org/pocs/cve-2026-100740

PoCbit

Catalog: https://pocbit.org/pocs/

Vendor / modelD-Link DIR-895L
FirmwareA1_102b07
ComponentL2TP control parser / tunnel.c
VectorCrafted Host Name AVP (len 127)
PortUDP 1701
CVSS 4.0VulDB PR:L, network, high impact

This PoC fingerprints the router (HTTP), checks UDP 1701, optionally sends a lab-only SCCRQ trigger (--oob-send). It does not ship a full RCE chain.

Usage

pip install -r requirements.txt

python poc.py -u 192.168.0.1 --mode check
python poc.py -u 192.168.0.1 --mode check --l2tp-probe
python poc.py -u 192.168.0.1 --mode exploit --oob-send
python poc.py --list targets.example.txt --mode check -j 20

GitHub About (EN)

CVE-2026-100740 PoC: D-Link DIR-895L A1_102b07 L2TP Host Name AVP out-of-bounds write (tunnel_set_params). Detects device, UDP 1701, optional OOB trigger packet. PoCbit

Özet (TR)

CVE-2026-100740: DIR-895L A1_102b07 L2TP parser’da Host Name AVP ile OOB write; uzaktan UDP 1701. PoC: tespit + lab’de --oob-send.

Legal

Authorized testing only. --oob-send may crash the router.

Download Tool