D-Link warned of two vulnerabilities affecting its DIR-822A routers, both discovered by a single researcher who also published proof-of-concept exploit code. The most severe, CVE-2026-86296, carries the highest CVSS score and stems from improper data handling in the DHCP server component. Attackers on the same local network can send crafted DHCP packets to trigger a stack-based buffer overflow, potentially crashing the DHCP daemon or executing arbitrary code.
A second critical flaw, CVE-2026-86510, involves an out-of-bounds write in the L2TP control message parser that can cause arbitrary memory corruption, but requires the device to be configured for L2TP or L2TPv6 WAN connectivity. D-Link stated it is investigating both issues and working on security patches.
In a Friday advisory, the company explained that a specially crafted request can cause data to exceed the available stack buffer when processed by the strcpy function in the udhcpcd component, warning that successful exploitation could affect confidentiality, integrity, or availability.
D-Link has not yet flagged active exploitation, but the company acknowledged that attackers often target vulnerable D-Link devices to infect them with malware for use in large-scale botnets conducting distributed denial-of-service (DDoS) attacks. Until patches are released, D-Link advises ensuring that DIR-822A routers are not exposed to the internet, restricting remote management access, and limiting administrative access to trusted systems via firewall or network-access controls.