Skip to content
D-Link Flags Max Severity Zero-Day in Legacy Router

D-Link Flags Max Severity Zero-Day in Legacy Router

Bankinfosecurity • September 22, 2026

Networking manufacturer D-Link is alerting customers of a maximum-severity zero-day flaw found in one of its legacy WiFi routers.

See Also: Airlines and Airports: Visibility Across OT, IoT, and IT

Tracked as CVE-2026-86296 , the flaw affects D-Link's DIR-822A router. It causes a stack-based buffer overflow in the lightweight Dynamic Host Configuration Protocol component of the device. The company said threat actors without credentials, authentication or user interaction who are connected to the same network can remotely exploit the overflow to shut down the DHCP daemon by sending users requests, possibly leading to remote code execution.

According to a Friday advisory , the issue deals with improper data handling on DIR-822A models running firmware version A_101. "Successful exploitation may cause memory corruption and could allow an attacker to affect the device’s confidentiality, integrity, or availability," D-Link warned.

CVE rated the vulnerability at the maximum score of 10.0 under CVSS v3.1 and v4.0.

Reported by security researcher tian, the flaw specifically involves the strcpy function found in udhcpcd/serverpacket.c . The memory corruption issue in udhcpcd/serverpacket.c could cause a malicious strcpy call in the server, allowing an unrestricted overflow of the stack buffer.

The company released a public proof-of-concept exploit code, leaving users at an increased risk of exploitation if they continue to operate through affected devices. No signs of exploitation in the wild have been reported.

No patch or firmware update is available. The company recommends users to "monitor the applicable D-Link regional support site for updated firmware or product-security guidance.”

Additionally, D-Link is reviewing the specific hardware revisions affected by the flaw, since router revisions typically require different firmware. Before installing any update or firmware provided by the company, users should confirm the model of their router and its exact hardware revision. Downloading improper firmware could end up doing more damage to the affected device.

D-Link will also advise users if a determination has been made over whether the device has reached end-of-life status and will no longer qualify for security updates or patching.

Copy Editor, Global Copy Desk

Sirico began his career in 2018 at his local publication, the Asbury Park Press. From 2021 to early 2025, Sirico served as an editor at Best Lawyers, collaborating with top-tier publications such as The Wall Street Journal, Bloomberg Law and Handelsblatt.

Extracted Entities

Attack Types (1)

Platforms (1)