D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
This security flaw stems from a stack-based buffer overflow and improper data handling in the DHCP server component and can be exploited without authentication or user interaction.
Attackers without valid credentials on the same local network can send crafted DHCP packets to the device, trigger the overflow, and potentially crash the DHCP daemon or achieve remote code execution on targeted devices.
D-Link also warned that the security researcher who found and reported the issue published a proof-of-concept (PoC) exploit, which may allow attackers to weaponize the vulnerability in the wild faster.
"A specially crafted request may cause data to exceed the available stack buffer when processed by the strcpy function. Successful exploitation may cause memory corruption and could allow an attacker to affect the device's confidentiality, integrity, or availability," the company explained in a Friday advisory.
"This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized."
D-Link is also investigating a second vulnerability with public PoC exploit code affecting DIR-822A routers, a critical out-of-bounds write (CVE-2026-86510) in the L2TP control message parser reported by the same researcher.
Threat actors with basic privileges may exploit CVE-2026-86510 to trigger arbitrary memory corruption by manipulating input data to cause an out-of-bounds write in attacks targeting devices configured to use L2TP or L2TPv6 WAN connectivity.
While D-Link is still investigating the two flaws and working on security patches, it advised customers to ensure their DIR-822A routers are not exposed online, restrict remote management access, and limit administrative access to trusted systems and users via firewall or network-access controls.
Although it has not flagged these vulnerabilities as exploited in attacks, attackers often target vulnerable D-Link devices, infect them with malware, and add them to large-scale botnets used for distributed denial-of-service (DDoS) attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) tracks 26 D-Link security flaws that have been or are still exploited in attacks, two of which ransomware gangs have also abused.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0
Comments (0)