D-Link DIR-822A Router Vulnerability Scores CVSS 10.0 With Public PoC Available
D-Link disclosed CVSS 10.0 unauthenticated stack buffer overflow in non-US DIR-822A routers with public PoC; no patch available yet.
D-Link advisory SAP10516 (published September 18, updated September 21) covers CVE-2026-86296, a stack-based buffer overflow in the udhcpcd component (serverpacket.c) of DIR-822A firmware A_101 caused by unsafe strcpy use, scored CVSS v3.1 and v4.0 at 10.0. A remote unauthenticated attacker with no user interaction could trigger memory corruption, and a public PoC exists. A second flaw, CVE-2026-86510 (CVSS 9.9), is an out-of-bounds write in the L2TP Control Message Parser's tunnel_set_params function requiring low privileges, also with a public PoC; both remain under investigation with no firmware fix released.
- CVE-2026-86296: CVSS 10.0 stack buffer overflow in DIR-822A udhcpcd, remotely exploitable without authentication
- Public proof-of-concept exploit available for both disclosed flaws
- Second flaw CVE-2026-86510 (CVSS 9.9) hits L2TP parser, needs low privileges
- No patch yet; D-Link advises removing internet exposure and restricting remote management
Vulnerabilities mentionedAll →
- CVE-2026-862969.31%Stack-Based Buffer Overflow in D-Link DIR-822A udhcpcd DHCP Componentpublished · D-Link DIR-822A
- CVE-2026-865108.6<1%Out-of-Bounds Write in D-Link DIR-822A L2TP Control Message Parser
Full article526 words · extracted from gbhackers.com · click to collapse
D-Link has announced a critical stack-based buffer overflow vulnerability affecting the non-US DIR-822A router, identified as CVE-2026-86296.
This vulnerability has received a maximum CVSS v3.1 score of 10.0 and a CVSS v4.0 score of 10.0. Furthermore, a public proof-of-concept (PoC) exploit is reportedly available.
The company published advisory SAP10516 on September 18 and updated it on September 21. D-Link’s security portal offers global security advisories, vulnerability responses, and product lifecycle notices at supportannouncement.us.dlink.
D-Link DIR-822A Router Vulnerability
According to the announcement, CVE-2026-86296 affects the router’s `udhcpcd` component in the reported firmware version A_101. The vulnerability resides in `udhcpcd/serverpacket.c`, where unsafe use of the `strcpy` function can allow specially crafted data to exceed the available stack buffer.
A remote, unauthenticated attacker could potentially exploit this vulnerability without requiring user interaction. Successful exploitation may lead to memory corruption, compromising the confidentiality, integrity, and availability of the affected router.
This flaw is classified under CWE-121, stack-based buffer overflow, and CWE-119, improper restriction of operations within the bounds of a memory buffer. The published CVSS v3.1 vector is as follows: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R
This vector indicates that exploitation can occur over a network with low attack complexity, no privileges, and no user interaction required. Additionally, the scope is marked as changed, signifying that exploitation could potentially impact resources beyond the initially vulnerable security authority.
D-Link’s advisory also identifies CVE-2026-86510, a separate critical out-of-bounds write vulnerability in the DIR-822A’s L2TP Control Message Parser. This issue affects the `tunnel_set_params` function and has received a CVSS v3.1 score of 9.9 and a CVSS v4.0 score of 9.4.
Unlike CVE-2026-86296, the L2TP flaw requires low-level privileges. However, it remains remotely accessible, requires no user interaction, and has a public PoC. This vulnerability is classified as CWE-787 (out-of-bounds write)) and CWE-119.
D-Link stated that both reports are still under investigation. The company is verifying the affected hardware revisions, geographic product scope, lifecycle status, and the potential for releasing an appropriate firmware update.
Currently, advisory SAP10516 indicates that the affected firmware version for DIR-822A is A_101. Organizations should not assume compatibility with firmware intended for other hardware revisions, as D-Link specifies that router models may exist in multiple revisions with different firmware requirements.
Until D-Link provides validated remediation guidance, DIR-822A operators should take the following actions:
- Verify the exact router model, hardware revision, and installed firmware version.
- Remove unnecessary Internet exposure, particularly administrative interfaces.
- Disable or restrict remote management services unless operationally required.
- Use firewall and network access controls to permit administration only from trusted systems.
- Monitor D-Link’s applicable regional support portal for updated firmware or lifecycle guidance.
- Install firmware only when it explicitly matches the router’s model and hardware revision.
This disclosure highlights the ongoing risk posed by memory-safety flaws in edge devices. Routers exposed to the Internet that have remotely accessible management or network services should be prioritized for exposure reduction, firmware verification, and network segmentation while the vendor’s investigation continues.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.