// 1 ZERO-DAY · 3 CVE · 4 EXPLOIT IN THE LAST 24H→
CVE-2026-100740 hits D-Link DIR-895L routers with a CVSS 9.9 score. The vendor declared the series End-of-Life in 2019, ruling out any firmware updates.

On September 27, 2026, vulnerability CVE-2026-100740 in the D-Link DIR-895L router firmware A1_102b07 was disclosed with a CVSS score of 9.9, the highest severity. The flaw, an out-of-bounds write in the L2TP Control Channel parser, could allow remote code execution if a confirmed exploit exists. D-Link had already declared the DIR-895L/R series End-of-Life and End-of-Service in 2019: no firmware will arrive. For users, only one vendor-documented option remains.

Source limitations: Technical details are not independently verifiable; available sources are editorial and conflict with each other. Editorial sources from the same domain provide contradictory information on public exploit availability. No independent primary technical sources exist for this CVE.

Key Takeaways
  • CVE-2026-100740 affects D-Link DIR-895L firmware A1_102b07 with CVSS 9.9 on the critical scale.
  • The vulnerability is an out-of-bounds write in the tunnel_set_params function of tunnel.c, part of the L2TP Control Channel Parser.
  • D-Link declared the DIR-895L/R series EOL/EOS effective January 1, 2019; firmware development has ceased.
  • Editorial sources converge on the technical mechanism but conflict on the actual availability of a public exploit.

The L2TP Parser Flaw and the CVSS 9.9 Score

The bug resides in the tunnel_set_params function in tunnel.c, a component of the L2TP Control Channel Parser. According to concurring editorial sources, the flaw is remotely triggerable via malformed L2TP control packets on UDP port 1701. The CVSS:3.1 vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H confirms that an attacker with low-level network access can compromise confidentiality, integrity, and availability to the maximum degree.

The CVSS 4.0 vector AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P documents the extended impact across the three pillars of cybersecurity. The S:C (scope changed) parameter in the CVSS 3.1 vector indicates that the compromise crosses the boundary of the vulnerable component. The source does not specify how this scope change manifests in the context of the DIR-895L router.

The EOL Trap: No Patch for Devices Unsupported Since 2019

D-Link published announcement SAP10299 defining the DIR-895L/R series as End-of-Life/End-of-Service. The official support cessation date is January 1, 2019, with the last firmware update released on September 20, 2026. The official document is clear: "all firmware development for these products cease." The vendor policy provides no exceptions for vulnerabilities discovered post-EOL.

The DIR-895L/R series, a high-end tri-band AC5300 router at launch, remains in residual use in home and small-office environments. The vendor, in the cited document, is explicit: "any further use of this product may be a risk to devices connected to it." The recommendation is not a workaround but outright retirement: "retired and replaced."

SAP10299 documents previous vulnerabilities in the same series: CVE-2025-69542 (DHCP command injection, CVSS 9.8), CVE-2026-86509 (CVSS 9.6), and CVE-2026-86295 (CVSS 8.3). None of these is the currently disclosed CVE-2026-100740. The source does not specify whether the new flaw is technically related to the previous ones.

"D-Link US recommends D-Link devices that have reached EOL/EOS, to be retired and replaced" — D-Link, announcement SAP10299

The Exploit Conflict: An Unresolvable Knowledge Gap

The availability of attack code is the most contentious element of the dossier. TheHackerWire, in two articles on the same domain, provides contradictory assertions. The first text states that "The exploit is now public and may be used"; the second, published later, asserts that "No standalone public exploit has been published in open research repositories at the time of writing."

This internal conflict within a single editorial source cannot be resolved on the merits with the available sources. As of September 27, 2026, CVE-2026-100740 does not appear in the CISA Known Exploited Vulnerabilities catalog. Absence from CISA KEV does not equal safety, but it constitutes the available verifiable datum.

TheHackerWire source reports an EPSS of 0.45% for the next thirty days. This value is low in context: EPSS is a probabilistic indicator separate from the CVSS framework; it estimates the likelihood of exploitation based on historical patterns, it does not confirm the existence of a current exploit.

What to Do Now

The following actions derive exclusively from the sources documented in the dossier:

  • Replace the device. The explicit recommendation from D-Link in SAP10299 is the retirement and replacement of the DIR-895L/R series; no patch is planned.
  • Verify the presence of firmware A1_102b07. The dossier identifies this version as affected; no other vulnerable versions are documented.
  • Assess limiting UDP/1701 exposure. The standard L2TP port is indicated as the attack vector in editorial sources; disabling the L2TP service is worth evaluating but is not confirmed as an effective mitigation.

Editorial Analysis: Industry Pattern, Not Case-Specific Data

This editorial analysis is based on industry patterns, not on data specific to the D-Link case.

The CVE-2026-100740 case fits a recurring dynamic in the consumer network device market. Vendors declare EOL on still-functional hardware, shifting the security cost to the end user. The DIR-895L, a high-end router at launch, now receives a critical vulnerability with no possibility of official remediation.

The frequency with which L2TP vulnerabilities emerge on D-Link products — the dossier cites CVE-2026-86510 on the DIR-822A with the same tunnel_set_params function — suggests a shared codebase across different firmware. This observation is, however, inferential: the brief provides no technical correlation data between the models.

For users, the operational lesson is simple: the EOL declaration has concrete security consequences. The vendor has explicitly stated that "any further use of this product may be a risk to devices connected to it." CVE-2026-100740 is not an exception to the rule, but the confirmation of the rule itself.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. secnews.gr
  2. thehackerwire.com
  3. cvefeed.io
  4. supportannouncement.us.dlink.com