HomeSecurityD-Link DIR-822A: Critical vulnerabilities threaten routers

D-Link DIR-822A: Critical vulnerabilities threaten routers

D -Link is investigating two critical security vulnerabilities in the DIR-822A router, which affect firmware version A_101 and could pose serious risks to devices exposed to the internet. The more serious of the two, CVE-2026-86296, has received a CVSS score of 10.0, the maximum possible value, as it can be exploited remotely without requiring authentication or user interaction.

D-Link DIR-822A

The issue takes on even greater importance due to the reported public availability of proof-of-concept code, which may facilitate the development of tools to identify and exploit vulnerable devices.

Memory error in udhcpcd

CVE-2026-86296 is located in the udhcpcd of the DIR-822A, specifically in the file udhcpcd/serverpacket.c. The vulnerability is related to a stack-based buffer overflow, as the code uses the strcpy to copy data that can be controlled by an attacker into a fixed-size buffer.

The problem occurs when the data being input exceeds the available memory capacity. In such a scenario, it is possible to write beyond the intended limits and affect adjacent memory areas.

See also:  Zyxel and Veeam: Actively exploiting critical vulnerabilities

A successful attack could cause anything from crash or shutdown a router to arbitrary code execution. The latter scenario is particularly serious, as a compromised router is located at a network hub and can offer the attacker significant opportunities for further attacks.

Why CVSS 10.0 is particularly worrisome

The published CVSS v3.1 vector is CVSS:3.1/AV/AC/PR/UI/S/C/I/A/E/RL/RC. Simply put, the attack can be carried out over a network, has low complexity, and does not require prior privileges or action from the victim.

At the same time, the exploit can affect all three key pillars of security: confidentiality, integrity, and availability. This means that an attacker could, depending on the exploit and the environment, gain access to data, modify functions, or cause service disruption.

The risk is greater when the device is accessible directly from the public internet, as there is not necessarily any additional layer of protection between the attacker and the vulnerable service.

Second critical vulnerability in the same router

D-Link has confirmed a second serious issue, CVE-2026-86510 , also affecting the DIR-822A version A_101. In this case, an out-of-bounds write is detected in the tunnel_set_params function of the L2TP Control Message Parser.

The vulnerability has a CVSS v3.1 score of 9.9 and a CVSS v4.0 score of 9.4. Exploitation requires low privileges, but no user interaction is required. Specially crafted L2TP control messages can potentially lead to memory corruption, creating the conditions for a serious compromise of the device.

In this case too, a publicly available proof-of-concept has been reported, an element that increases the need for immediate evaluation of the report.

D-Link DIR-822A: Critical vulnerabilities threaten routers

What should DIR-822A owners do?

Until D-Link clarifies all affected hardware revisions and there are definitive guidance or fixes available, organizations and users should limit the attack surface as much as possible.

See also:  CVE-2026-76461: Critical zero-day in Cisco Secure Email Gateway

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The first step is to check the exact model, hardware revision, and installed firmware version. Remote router management should be disabled when not absolutely necessary, and access to the management interface should be limited to trusted systems and networks.

Additionally, corporate network administrators should examine whether the specific router is accessible from the internet and look for unusual activity, failed connection attempts , or unexpected configuration changes.

Be careful with firmware updates

D-Link notes that firmware is specifically linked to the corresponding hardware revision. Therefore, installing a firmware image intended for a different hardware revision may cause malfunction, even permanent damage to the device, while also not providing the expected protection.

DIR-822A owners should monitor D-Link's official local support portal for new firmware releases and security guidelines.

Another example of the danger of older routers

This case highlights a broader problem: routers often remain in operation for years, while users do not treat them with the same care they give computers and smartphones. However, a vulnerable router can be a significant entry point into an entire network.

See also: Muse dictation: Critical local vulnerability in macOS

The existence of two critical vulnerabilities in the same equipment, combined with reports of a public proof-of-concept, makes monitoring the exposure particularly important. Until more information is available from D-Link, the safest approach is to restrict remote access and closely monitor for available fixes.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS