D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link disclosed CVSS 10.0 unauthenticated stack buffer overflow in non-US DIR-822A routers with public PoC; no patch available yet.
D-Link advisory SAP10516 (published September 18, updated September 21) covers CVE-2026-86296, a stack-based buffer overflow in the udhcpcd component (serverpacket.c) of DIR-822A firmware A_101 caused by unsafe strcpy use, scored CVSS v3.1 and v4.0 at 10.0. A remote unauthenticated attacker with no user interaction could trigger memory corruption, and a public PoC exists. A second flaw, CVE-2026-86510 (CVSS 9.9), is an out-of-bounds write in the L2TP Control Message Parser's tunnel_set_params function requiring low privileges, also with a public PoC; both remain under investigation with no firmware fix released.