Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

D-Link warns of max-severity zero-day in DIR-822A routers

D-Link has warned customers about a maximum-severity vulnerability, CVE-2026-86296, affecting legacy DIR-822A dual-band Wi-Fi routers. The flaw has public proof-of-concept (PoC) exploit code, and no security patch is available.

The vulnerability is caused by a stack-based buffer overflow and improper data handling in the DHCP server component. An attacker on the same local network could send crafted DHCP packets without authentication or user interaction. Successful exploitation could crash the DHCP daemon or potentially enable remote code execution.

D-Link said the researcher who reported the issue has published a PoC that could help attackers weaponize it faster. The company is also investigating a second vulnerability, CVE-2026-86510, involving a critical out-of-bounds write in the L2TP control message parser. Attackers with basic privileges could exploit it against routers configured to use L2TP or L2TPv6 WAN connectivity.

D-Link is working on patches and advised customers to keep DIR-822A routers off the public internet, restrict remote management, and limit administrative access through firewall or network controls. The company has not reported attacks exploiting either flaw. CISA tracks 26 D-Link flaws that have been or remain exploited, including two also abused by ransomware groups.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.