ZeroHour

CVE-2026-86510

large

Out-of-Bounds Write in D-Link DIR-822A L2TP Control Message Parser

CVSS 4.0
8.6 high
EPSS
<1%p39
Published
()
Modified
AI analysis

CVE-2026-86510 is an out-of-bounds write (CWE-119/CWE-787) in the tunnel_set_params function of the L2TP Control Message Parser in D-Link DIR-822A firmware A_101. It is triggered when the parser handles crafted L2TP control messages; the CVSS 4.0 vector (AV:N/PR:L/UI:N) indicates the attack can be launched remotely over the network with low privileges and no user interaction. Successful exploitation corrupts memory beyond the intended buffer, and the high impact ratings in the CVSS score suggest it could lead to full device compromise or denial of service. Owners of D-Link DIR-822A routers are potentially affected, with exposure concentrated on devices that process L2TP control traffic (commonly used for ISP VPN-style connections). The exploit has been disclosed publicly and may be used, though the flaw is not yet in CISA KEV and EPSS currently assigns a 0.5% probability of exploitation within 30 days (39th percentile).

What to do: Check D-Link's support site for updated firmware for the DIR-822 A-series hardware and upgrade as soon as a patched release is available; no fixed version is named in the available data. Until patched, reduce exposure by disabling L2TP (or restricting UDP 1701 to trusted ISP endpoints only) and avoid exposing the router's management interface to the internet. Owners of this older model should note it may be near or past end-of-life, in which case replacing the device is the most reliable remediation.

Affected
D-Link DIR-822A (A-series hardware)
Estimated exposure
large≈100,000–1,000,000 units worldwide (estimate; L2TP-exposed subset unknown) — Based on deployment pattern: the DIR-822 A-series was a mass-market consumer wireless router sold through global retail channels in the mid-2010s, implying an installed base plausibly in the hundreds of thousands, though no public scan…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Weakness
CWE-119, CWE-787
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.