BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 22, 2026 · 2 min read · Original story

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.

This security flaw stems from a stack-based buffer overflow and improper data handling in the DHCP server component and can be exploited without authentication or user interaction.

Attackers without valid credentials on the same local network can send crafted DHCP packets to the device, trigger the overflow, and potentially crash the DHCP daemon or achieve remote code execution on targeted devices.

D-Link also warned that the security researcher who found and reported the issue published a proof-of-concept (PoC) exploit, which may allow attackers to weaponize the vulnerability in the wild faster.

"A specially crafted request may cause data to exceed the available stack buffer when processed by the strcpy function. Successful exploitation may cause memory corruption and could allow an attacker to affect the device's confidentiality, integrity, or availability," the company explained in a Friday advisory.

"This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized."

D-Link is also investigating a second vulnerability with public PoC exploit code affecting DIR-822A routers, a critical out-of-bounds write (CVE-2026-86510) in the L2TP control message parser reported by the same researcher.

Threat actors with basic privileges may exploit CVE-2026-86510 to trigger arbitrary memory corruption by manipulating input data to cause an out-of-bounds write in attacks targeting devices configured to use L2TP or L2TPv6 WAN connectivity.

While D-Link is still investigating the two flaws and working on security patches, it advised customers to ensure their DIR-822A routers are not exposed online, restrict remote management access, and limit administrative access to trusted systems and users via firewall or network-access controls.

Although it has not flagged these vulnerabilities as exploited in attacks, attackers often target vulnerable D-Link devices, infect them with malware, and add them to large-scale botnets used for distributed denial-of-service (DDoS) attacks.

The Cybersecurity and Infrastructure Security Agency (CISA) tracks 26 D-Link security flaws that have been or are still exploited in attacks, two of which ransomware gangs have also abused.

References in this story

  1. NVD - Home nvd.nist.gov
  2. Notion | Where teams and agents work together tzh00203.notion.site A collaborative AI workspace, built on your company context. Build and orchestrate agents right alongside your team
  3. D-Link Technical Support supportannouncement.us.dlink.com
  4. Notion | Where teams and agents work together tzh00203.notion.site A collaborative AI workspace, built on your company context. Build and orchestrate agents right alongside your team
  5. NVD - Home nvd.nist.gov
  6. RondoDox botnet targets 56 n-day flaws in worldwide attacks www.bleepingcomputer.com A new large-scale botnet called RondoDox is targeting 56 vulnerabilities in more than 30 distinct devices, including flaws first disclosed during Pwn2Own hacking competitions.
  7. Malware botnets exploit outdated D-Link routers in recent attacks www.bleepingcomputer.com Two botnets tracked as 'Ficora' and 'Capsaicin' have recorded increased activity in targeting D-Link routers that have reached end of life or are running outdated firmware versions.
  8. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…

← Back to all news