Find notable cyber news and cases, enriched with sources, timelines, and signals.

D-Link DIR-822A DHCP stack-based buffer overflow remote code execution flaw (CVE-2026-86296)

Vulnerability
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

The D-Link DIR-822A vulnerability CVE-2026-86296 exposes legacy dual-band routers to unauthenticated attacks that can crash the DHCP daemon or enable remote code execution. The flaw is a stack-based buffer overflow in the DHCP server component and can be triggered with crafted DHCP packets from the same local network. Public PoC exploit code is already available, and no patch was available at disclosure.

Related Happenings

DIR-822A L2TP control message parser out-of-bounds write memory corruption flaw (CVE-2026-86510)

Vulnerability
H score31 First: 22.09.2026 15:48 Last: 22.09.2026 15:48 Sources 1

How related: D-Link is also investigating a second vulnerability with public PoC exploit code affecting DIR-822A routers, a critical out-of-bounds write (CVE-2026-86510) in the L2TP control message parser reported by the same researcher.

About this happening: D-Link is investigating CVE-2026-86510, a critical out-of-bounds write in the L2TP control message parser of DIR-822A routers that can let attackers with basic pri...

Timeline

  1. 22.09.2026 15:48 2 articles · 0h ago

    D-Link warns of CVE-2026-86296 in DIR-822A routers

    Initial Disclosure

    D-Link warned customers about CVE-2026-86296 in legacy DIR-822A dual-band Wi-Fi routers, saying the flaw has public proof-of-concept exploit code and no patch. The issue is a stack-based buffer overflow and improper data handling in the DHCP server component, where specially crafted DHCP requests can exceed the available stack buffer in strcpy, potentially causing memory corruption, a DHCP daemon crash, or remote code execution without authentication or user interaction. D-Link advised keeping DIR-822A routers off the internet, restricting remote management access, and limiting administrative access through firewall or network-access controls while it continues investigating and preparing security patches.

    Show sources