CVE-2026-86510: out-of-bounds write in D-Link DIR-822A L2TP daemon
Firmware A_101 for the D-Link DIR-822A router contains an out-of-bounds write in the L2TP control message parser (CVE-2026-86510, CVSS 9.9). A second flaw, CVE-2026-86296, scores 10.0; working PoC code is public and no patch is available yet.
- CVE-2026-86510 is an out-of-bounds write in tunnel_set_params, CVSS 9.9
- Companion flaw CVE-2026-86296 in the same firmware scores 10.0
- Exploitation requires local network access; no in-the-wild attacks confirmed
- Firmware A_101 is affected and D-Link has not released a fix
Read next
Security