CVE-2026-86509
nicheLAN-side stack buffer overflow in D-Link DIR-895L udhcpcd DHCP daemon
CVE-2026-86509 is a stack-based buffer overflow (CWE-121/CWE-119) in the sendOffer/sendACK functions of udhcpcd/serverpacket.c on the D-Link DIR-895L router running firmware A1_102b07. An attacker who is already on the local network can send crafted DHCP traffic that causes the router's DHCP daemon to construct oversized server reply packets (OFFER/ACK), overflowing a stack buffer with no authentication or user interaction required. Successful exploitation carries high impact for confidentiality, integrity, and availability per the CVSS 4.0 score of 8.6, potentially allowing arbitrary code execution on the router or at minimum crashing the DHCP service. Only deployments of the D-Link DIR-895L are implicated by the current data, and because the attack vector is adjacent (AV:A), internet-facing exposure is not the concern — untrusted devices on the LAN are. An exploit has been published and may be used, though EPSS puts near-term exploitation probability at just 0.4% and the flaw is not in CISA's KEV catalog.
What to do: Check the firmware revision on any DIR-895L you manage and, since the data does not specify a fixed version, consult D-Link's support page for hardware revision A1 and apply the latest firmware update as soon as it addresses this issue. Until patched, limit the LAN to trusted clients (e.g., place guest, IoT, or contractor devices on a segregated network) because exploitation requires nothing more than local network reachability. Given the published exploit but low EPSS and no KEV listing, treat this as a routine patch-cycle item unless DIR-895L units sit on networks with untrusted LAN users.
| D-Link DIR-895L | A1_102b07 (hardware revision A1, firmware 102b07 as reported; no other confirmed version ranges in the data) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.
- Weakness
- CWE-119, CWE-121
- Vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.