ZeroHour

CVE-2026-86296

moderate

Stack-Based Buffer Overflow in D-Link DIR-822A udhcpcd DHCP Component

CVSS 4.0
9.3 critical
EPSS
1%p70
Published
()
Modified
AI analysis

CVE-2026-86296 is a remotely exploitable stack-based buffer overflow (CWE-121, CWE-119) in the strcpy call within the file udhcpcd/serverpacket.c, part of the udhcpcd DHCP component on the D-Link DIR-822A router running firmware A_101. An attacker triggers the flaw by sending crafted network data that is processed by the router's udhcpcd DHCP packet-handling code, overflowing a fixed-size stack buffer without requiring authentication or user interaction. Successful exploitation can crash the daemon or potentially allow arbitrary code execution, giving an attacker high-impact control over the device (high confidentiality, integrity, and availability impact per the CVSS 4.0 score of 9.3). Only D-Link DIR-822A devices running the affected firmware A_101 are implicated by this advisory. The advisory notes the exploit has been publicly disclosed and may be utilized, though no dedicated public PoC is catalogued and the issue is not yet in CISA KEV; EPSS estimates a 1.3% probability of exploitation in the next 30 days.

What to do: Check the firmware version on any DIR-822A in your environment (the admin UI displays it) and, if it is A_101, monitor the D-Link support page for a fixed release, as the advisory does not specify a patched version. Until a fix is applied, minimize untrusted DHCP traffic reaching the WAN-facing component and consider prioritizing replacement of this older router given the critical severity. Watch for the issue's addition to CISA KEV or a rise in EPSS as signals of active exploitation.

Affected
D-Link DIR-822AA_101
Estimated exposure
moderatetens of thousands of units still deployed (single discontinued consumer router model; no public scan counts available) — estimate — Based on deployment patterns rather than scan data: the DIR-822A is a single consumer router model shipped in volume in the mid-2010s, so remaining in-service units running the affected A_101 firmware are plausibly in the tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

Weakness
CWE-119, CWE-121
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.