D-Link Warns of Maximum-Severity Zero-Day in DIR-822A Routers
Share
D-Link has issued an advisory regarding a maximum-severity zero-day vulnerability affecting its legacy DIR-822A dual-band Wi-Fi routers. The flaw, identified as CVE-2026-86296, has a publicly available proof-of-concept (PoC) exploit, but the manufacturer has not yet released a security patch.
The vulnerability is a stack-based buffer overflow within the DHCP server component (udhcpcd). Specifically, the flaw affects the strcpy function within the udhcpcd/serverpacket.c file. An attacker located on the same local network can exploit this by sending specially crafted DHCP packets to the device to trigger the overflow.
Successful exploitation could allow an attacker to achieve remote code execution (RCE), cause memory corruption, or crash the DHCP daemon. Such an attack could compromise the confidentiality, integrity, and availability of the targeted device.
Second critical vulnerability under investigation
D-Link is also investigating a second critical vulnerability, CVE-2026-86510, which also has public PoC exploit code. This issue involves an out-of-bounds write in the L2TP control message parser. Threat actors with basic privileges could exploit this flaw to cause arbitrary memory corruption on devices configured to use L2TP or L2TPv6 WAN connectivity.
While D-Link has not confirmed that these vulnerabilities are being actively exploited in the wild, the existence of public exploit code increases the risk of rapid weaponisation. Threat actors have historically targeted vulnerable D-Link hardware to build large-scale botnets used for distributed denial-of-service (DDoS) attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) currently tracks 26 security flaws associated with D-Link products, some of which have been abused by ransomware gangs.
Mitigation steps for affected users
As D-Link works to develop security patches, the company has advised customers to implement the following measures to reduce risk:
- Ensure DIR-822A routers are not exposed to the public internet.
- Restrict all remote management access.
- Limit administrative access to trusted systems and users via firewalls or network-access controls.




Leave a Reply