Critical D-Link DIR-822A Router Vulnerabilities Expose Devices to Remote Exploitation
D-Link has disclosed two critical vulnerabilities in its non-US DIR-822A router, including a stack-based buffer overflow flaw (CVE-2026-86296) with a maximum CVSS score of 10.0 and a public proof-of-concept (PoC) exploit. The vulnerabilities were detailed in advisory SAP10516, published on September 18 and updated on September 21.
The primary flaw, CVE-2026-86296, affects the router’s udhcpcd component in firmware version A_101, stemming from unsafe use of the strcpy function in udhcpcd/serverpacket.c. A remote, unauthenticated attacker could exploit this to trigger memory corruption, compromising the router’s confidentiality, integrity, and availability. The vulnerability is classified under CWE-121 (stack-based buffer overflow) and CWE-119 (improper memory bounds restriction), with a CVSS v3.1 vector indicating network-based exploitation with no privileges or user interaction required.
A second critical vulnerability, CVE-2026-86510, involves an out-of-bounds write flaw in the L2TP Control Message Parser (tunnel_set_params), scoring 9.9 (CVSS v3.1) and 9.4 (CVSS v4.0). Unlike the first flaw, this requires low-level privileges but remains remotely exploitable with a public PoC. It is classified under CWE-787 (out-of-bounds write) and CWE-119.
D-Link is still investigating the affected hardware revisions, geographic scope, and potential firmware updates. The advisory warns that firmware compatibility varies by hardware revision, and users should verify their exact model and version before applying updates. Until remediation is available, D-Link recommends reducing internet exposure, disabling remote management, and restricting administrative access to trusted systems.
The disclosure underscores risks posed by memory-safety flaws in edge devices, particularly routers with exposed management interfaces. Organizations are advised to monitor D-Link’s regional support portals for updates while the investigation continues.
Source: https://gbhackers.com/d-link-dir-822a-router-vulnerability/
D-Link cybersecurity rating report: https://www.rankiteo.com/company/dlink-corp
"id": "DLI1790073409",
"linkid": "dlink-corp",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Networking Hardware',
'location': 'Global (non-US)',
'name': 'D-Link',
'type': 'Vendor'}],
'attack_vector': 'Network',
'customer_advisories': 'Advisory SAP10516 published and updated with '
'mitigation recommendations',
'date_publicly_disclosed': '2024-09-18',
'description': 'D-Link has disclosed two critical vulnerabilities in its '
'non-US DIR-822A router, including a stack-based buffer '
'overflow flaw (CVE-2026-86296) with a maximum CVSS score of '
'10.0 and a public proof-of-concept (PoC) exploit. The '
'vulnerabilities were detailed in advisory SAP10516, published '
'on September 18 and updated on September 21. The primary '
'flaw, CVE-2026-86296, affects the router’s `udhcpcd` '
'component in firmware version A_101, stemming from unsafe use '
'of the `strcpy` function. A remote, unauthenticated attacker '
'could exploit this to trigger memory corruption, compromising '
'the router’s confidentiality, integrity, and availability. A '
'second critical vulnerability, CVE-2026-86510, involves an '
'out-of-bounds write flaw in the L2TP Control Message Parser, '
'scoring 9.9 (CVSS v3.1). D-Link is investigating the affected '
'hardware revisions, geographic scope, and potential firmware '
'updates.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'critical vulnerabilities',
'operational_impact': 'Potential compromise of confidentiality, '
'integrity, and availability of affected '
'routers',
'systems_affected': 'D-Link DIR-822A routers (non-US models)'},
'investigation_status': 'Ongoing',
'lessons_learned': 'Risks posed by memory-safety flaws in edge devices, '
'particularly routers with exposed management interfaces.',
'post_incident_analysis': {'corrective_actions': ['Pending firmware updates',
'Hardware revision and '
'geographic scope '
'investigation'],
'root_causes': ['Unsafe use of `strcpy` function '
'in `udhcpcd/serverpacket.c` '
'(CVE-2026-86296)',
'Out-of-bounds write flaw in L2TP '
'Control Message Parser '
'(CVE-2026-86510)']},
'recommendations': ['Monitor D-Link’s regional support portals for updates',
'Verify exact model and version before applying updates',
'Reduce internet exposure of affected devices',
'Disable remote management',
'Restrict administrative access to trusted systems'],
'references': [{'date_accessed': '2024-09-21',
'source': 'D-Link Advisory SAP10516'}],
'response': {'communication_strategy': 'Advisory SAP10516 published and '
'updated',
'containment_measures': ['Reducing internet exposure',
'Disabling remote management',
'Restricting administrative access to '
'trusted systems'],
'remediation_measures': 'Firmware updates (pending '
'investigation)'},
'title': 'Critical D-Link DIR-822A Router Vulnerabilities Expose Devices to '
'Remote Exploitation',
'type': ['Vulnerability Disclosure', 'Memory Corruption'],
'vulnerability_exploited': ['CVE-2026-86296', 'CVE-2026-86510']}