chiprook
← Security
SecuritySeptember 27, 2026, 09:20

CVE-2026-86510: out-of-bounds write in D-Link DIR-822A L2TP daemon

Firmware A_101 for the D-Link DIR-822A router contains an out-of-bounds write in the L2TP control message parser (CVE-2026-86510, CVSS 9.9). A second flaw, CVE-2026-86296, scores 10.0; working PoC code is public and no patch is available yet.

CVE-2026-86510: out-of-bounds write in D-Link DIR-822A L2TP daemon
#D-Link
Read next
Security

D-Link warns of max severity zero-day in DIR-822A routers

Security

Router Privacy Index 2026: 100% of brands fail to disclose DNS logging

Security

Vicarius launches ScriptAI to write fixes for flaws with no vendor patch

Security

Linux KVM ARM64 Flaw Lets Guests Read and Write Host Memory