A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument peer_hostname leads to off-by-one. The attack may be performed from remote. Attacks of this nature are highly complex. The exploitability is assessed as difficult. The exploit is publicly available and might be used.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-86297 is a remote off-by-one error in the L2TP (Layer 2 Tunneling Protocol) control message parser of D-Link DIR-605 B1 routers. The vulnerability exists in the tunnel_set_params function where improper handling of the peer_hostname argument creates a one-byte buffer overflow condition. This affects network infrastructure devices commonly deployed in small office and home environments, making any organization relying on these routers for VPN termination or L2TP services potentially at risk. While exploitation is complex and requires deep protocol knowledge, the public availability of exploit code increases the likelihood of weaponization.
While this CVE does not map to specific MITRE ATT&CK techniques in public threat intelligence, Casky's 754 mapped security skills enable practitioners to identify attack precursors through behavioral analysis of L2TP protocol anomalies. Extended reasoning across Casky's skill library would flag indicators such as malformed tunnel parameter parsing attempts, unexpected peer_hostname string lengths during L2TP negotiation, and memory access patterns consistent with off-by-one exploitation. Practitioners monitoring DIR-605 devices would receive findings highlighting unusual L2TP control message sequences, failed tunnel establishment with oversized hostname parameters, and potential code execution attempts—allowing detection of pre-exploitation reconnaissance or active compromise before successful payload delivery occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-86297. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation