Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2988+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. D-Link Warns of Max Severity Zero-Day Bug in DIR-822A Routers
D-Link Warns of Max Severity Zero-Day Bug in DIR-822A Routers
NEWS

D-Link Warns of Max Severity Zero-Day Bug in DIR-822A Routers

D-Link disclosed two unpatched flaws in legacy DIR-822A routers with public PoC exploit code, including a max-severity DHCP stack overflow.

Dylan H.

News Desk

September 22, 2026
2 min read

No Patch, Public Exploit Code, Maximum Severity

D-Link has warned customers of a maximum-severity vulnerability affecting legacy DIR-822A dual-band Wi-Fi routers — with public proof-of-concept exploit code already circulating and no patch available.


Vulnerability Summary

FieldDetails
Primary CVECVE-2026-86296
Secondary CVECVE-2026-86510
Affected DeviceD-Link DIR-822A (legacy, dual-band Wi-Fi router)
Exploit CodePublicly available (both flaws)
Patch StatusNone — D-Link investigating

CVE-2026-86296 — DHCP Server Stack Overflow

The primary flaw is a stack-based buffer overflow in the router's DHCP server component. It stems from the strcpy function in udhcpcd/serverpacket.c, where attacker-controlled data can exceed the available stack buffer, corrupting memory and potentially enabling remote code execution.

CVE-2026-86510 — L2TP Parser Out-of-Bounds Write

A secondary out-of-bounds write vulnerability exists in the router's L2TP control message parser, affecting devices configured for L2TP or L2TPv6 WAN connectivity.


Why This Matters

The DIR-822A is a legacy product, meaning D-Link may be slower — or may decline entirely — to ship a fix depending on the device's end-of-life status. With public PoC code already available for both bugs, opportunistic scanning and exploitation attempts against internet-exposed devices are likely to follow quickly.


Mitigation

Since no patch currently exists, D-Link and researchers recommend:

  • Do not expose the router's management interface to the internet
  • Restrict remote management access entirely where possible
  • Limit administrative access via firewall rules to trusted internal systems only
  • Consider replacing end-of-life hardware that no longer receives regular security updates
  • Disable L2TP WAN configuration if not actively required, to reduce exposure to CVE-2026-86510

Sources

  • BleepingComputer — D-Link Warns of Max Severity Zero-Day Bug in DIR-822A Routers
#D-Link#Zero-Day#Router Security#CVE-2026-86296#IoT Security

Related Articles

Critical Stack Overflow in D-Link DIR-823G Routers (CVE-2026-90680)

An unauthenticated stack-based buffer overflow (CVSS 9.9) in D-Link DIR-823G's HNAP1 interface allows remote attackers to corrupt memory...

4 min read

CVE-2026-94089: Critical Unauthenticated Stack Overflow in D-Link DIR-868L Routers

A CVSS 10 stack-based buffer overflow in D-Link DIR-868L's authentication CGI lets unauthenticated remote attackers achieve full router compromise.

3 min read

D-Link DIR-825M Disk-Format Stack Overflow (CVE-2026-82592)

CVE-2026-82592 is a critical, unauthenticated stack overflow in D-Link DIR-825M's disk-formatting endpoint, with a public exploit available.

4 min read
Back to all News