Two critical flaws found in D-Link DIR-822A router
Two memory-safety bugs were disclosed in the D-Link DIR-822A router on firmware A_101, both with public proof-of-concept code: a stack buffer overflow in the DHCP server (CVE-2026-86296, CVSS 10.0) and an out-of-bounds write in the L2TP parser (CVE-2026-86510, CVSS 9.9). Both require LAN access and can crash the device or lead to code execution. No patch is available yet.
- CVE-2026-86296: DHCP stack overflow rated 10.0
- CVE-2026-86510: L2TP out-of-bounds write rated 9.9
- Affects DIR-822A running firmware A_101
- Working PoCs published; no fix from D-Link yet
Read next
Security