Two critical flaws found in D-Link DIR-822A firmware
D-Link DIR-822A routers running firmware A_101 are affected by CVE-2026-86510 (out-of-bounds write in the L2TP parser, scored 9.9) and CVE-2026-86296 (stack buffer overflow in the DHCP server, 10.0). No patch exists yet; public PoCs are available but no in-the-wild exploitation has been confirmed.
- CVE-2026-86510 is an out-of-bounds write in the L2TP parser, scored 9.9
- CVE-2026-86296 is a stack buffer overflow in the DHCP server, scored 10.0
- Both affect firmware A_101 and remain unpatched
- ZoomEye returned 624 assets for the query title="DIR-822"
Read next
Security