D-Link warns of max severity zero-day in DIR-822A routers
D-Link disclosed a maximum-severity flaw (CVE-2026-86296) in legacy DIR-822A routers: a stack-based buffer overflow in the udhcpcd DHCP server that can be exploited without authentication. No patch exists and a public PoC is available; D-Link is also investigating a second flaw, CVE-2026-86510, in the L2TP parser.
- CVE-2026-86296: stack overflow in udhcpcd, no auth needed
- Public PoC exploit released, no patch available yet
- Second flaw CVE-2026-86510 is an out-of-bounds write in L2TP parser
- D-Link urges users to keep routers offline and limit remote access
Read next
Security