L2tpd is a focused Layer 2 Tunneling Protocol daemon implementation commonly deployed in VPN and remote-access environments on Unix and Linux systems. The observed vulnerability profile centers on the core l2tpd product, with reported weaknesses spanning a range of implementation issues in protocol handling and system interaction. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by L2tpd over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0649HIGH Buffer overflow in write_packet in control.c for l2tpd may allow remote attackers to execute arbitrary code. | Aug 6, 2004 | 10.0 | 32 | NO | NO |
CVE-2002-0872HIGH l2tpd 0.67 does not initialize the random number generator, which allows remote attackers to hijack sessions. | Sep 5, 2002 | 7.5 | 24 | NO | NO |
CVE-2002-0873MEDIUM Vulnerability in l2tpd 0.67 allows remote attackers to overwrite the vendor field via a long value in an attribute/value pair, possibly via a buffer overflow. | Sep 5, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by L2tpd.
Media articles that mention a CVE ID that affects a product developed by L2tpd — matched by CVE ID, not by vendor name.