D-Link Router Hit by CVSS 10.0 Flaw Exploitable Remotely Without Authentication
D-Link Systems has disclosed that it is investigating a critical security vulnerability in its DIR-822A router, tracked as CVE-2026-86296. The flaw has received the maximum CVSS severity score of 10.0. It may allow remote attackers to compromise vulnerable devices without authentication or user interaction.
The issue affects the udhcpcd component in the reported DIR-822A firmware version A_101. It is a stack-based buffer overflow in the udhcpcd/serverpacket.c source file, where the unsafe strcpy function is used to copy attacker-controlled data into a fixed-size stack buffer.
If the crafted input exceeds the available buffer space, it can overwrite adjacent memory. This condition can cause device crashes, service disruption, or potentially allow an attacker to run unauthorized code on the router.
D-Link said it is investigating the vulnerability, and it has not yet confirmed the affected hardware revisions, regional product scope, or firmware remediation status.
CVE-2026-86296 is classified under CWE-121, Stack-Based Buffer Overflow, and CWE-119, Improper Restriction of Operations within the Bounds of a Memory Buffer. The published CVSS v3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R.
The vector indicates that the attack can be launched across a network with low attack complexity. Attackers do not need valid credentials, local network access, or victim interaction.
D-Link Router Hit by CVSS 10.0 Flaw
Successful exploitation could affect confidentiality, integrity, and availability, making the vulnerability particularly serious for routers exposed directly to the public internet.
A public proof-of-concept exploit has reportedly been released. Such disclosures can increase the likelihood of active exploitation, as attackers may adapt public research into scanning or attack tools.
Organizations using the affected router should therefore treat the issue as an urgent exposure-management concern even while D-Link continues its validation work.
D-Link also confirmed a second critical flaw affecting the same reported DIR-822A A_101 version. Tracked as CVE-2026-86510, the vulnerability is an out-of-bounds write in the tunnel_set_params function of the L2TP Control Message Parser. It has a CVSS v3.1 score of 9.9 and a CVSS v4.0 score of 9.4.
Unlike CVE-2026-86296, exploiting CVE-2026-86510 requires low privileges, though it does not require user interaction. The flaw may enable memory corruption through specially crafted L2TP control messages. A public proof-of-concept has also been reported.
D-Link recommends that DIR-822A owners verify their exact model, hardware revision, and installed firmware version before taking action. Users should avoid exposing router administration interfaces to the internet, turn off remote management when it is not essential, and restrict administrative access to trusted systems.
Customers should monitor their applicable regional D-Link support portal for firmware updates or product-security guidance. D-Link warned that firmware is hardware-revision specific and installing an image intended for a different revision may damage the device or leave it unprotected.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
