Vulnerabilidad · Publicado 24/09/2026
Se identificó una vulnerabilidad de severidad crítica (CVSS 9.8) en el enrutador D-Link DIR-825 versión 3.00b32, específicamente en la función tunnel_set_params del componente rp-l2tp. Un atacante remoto puede explotar el parámetro peer_hostname para ejecutar escritura fuera de límites de memoria, comprometiendo la integridad del dispositivo. Esta vulnerabilidad afecta principalmente infraestructuras de pequeñas y medianas empresas en LATAM que utilizan este modelo como gateway de acceso.
A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipulation of the argument peer_hostname leads to out-of-bounds write. The attack may be initiated remotely.
Score: 9.8/10 — Severidad: CRITICAL — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-119, CWE-787
Publicado en NIST NVD.