D-Link Warns of Critical DIR-822A Router Vulnerabilities With Public PoC Exploits
D-Link is warning customers about two vulnerabilities affecting its legacy DIR-822A dual-band Wi-Fi router. One of the flaws, CVE-2026-86296, is described as maximum severity and has publicly available proof-of-concept (PoC) exploit code. The vulnerability remains unpatched.
Unauthenticated attack can target the DHCP service
CVE-2026-86296 is a stack-based buffer overflow caused by improper data handling in the router’s DHCP server component. The flaw can be exploited without authentication or user interaction.
An attacker without valid credentials on the same local network could send specially crafted DHCP packets to the DIR-822A. Successful exploitation could crash the DHCP daemon or enable remote code execution on the targeted device.
The vulnerability affects the strcpy function in udhcpcd/serverpacket.c, part of the udhcpcd component. D-Link said a specially crafted request could exceed the available stack buffer, causing memory corruption that affects the confidentiality, integrity, or availability of the device.
The security researcher who discovered the issue has published PoC exploit code for the D-Link DIR-822A vulnerability. Publicly available exploit code could allow attackers to develop attacks more quickly.
Second flaw affects L2TP and L2TPv6 configurations
D-Link is also investigating a second vulnerability, CVE-2026-86510. The critical out-of-bounds write affects the router’s L2TP control message parser and was reported by the same researchers.
An attacker with basic privileges could exploit the flaw by manipulating input data, causing arbitrary memory corruption and potentially triggering an out-of-bounds write on devices configured to use L2TP or L2TPv6 WAN connections. Public PoC exploit code is available for this vulnerability as well.
D-Link recommends restricting router access
D-Link is still investigating both vulnerabilities and working on security patches. In the meantime, the company recommends that customers:
- Prevent DIR-822A routers from being exposed directly to the internet.
- Limit remote administrative access.
- Restrict administrative access to trusted systems and users through firewalls and network access controls.
Neither vulnerability has been flagged as actively exploited. However, attackers frequently target vulnerable D-Link devices to install malware and add them to large botnets used in distributed denial-of-service (DDoS) attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) tracks 26 D-Link security flaws in its Known Exploited Vulnerabilities catalog. Two of those vulnerabilities have been exploited by ransomware gangs.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a 2-hour digital summit about what will change with AI speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



