D-Link Warns of Critical, Unpatched Vulnerabilities in Legacy DIR-822A Routers with Public Exploits
D-Link has issued a critical warning regarding two high-severity vulnerabilities affecting its legacy **DIR-822A** dual-band Wi-Fi routers. Both flaws, including a maximum-severity stack-based buffer overflow, have publicly available proof-of-concept (PoC) exploit code, significantly increasing the risk of in-the-wild exploitation before patches are released. The company urges users to implement immediate mitigation strategies.
Router manufacturer **D-Link** has alerted customers to a critical, unpatched vulnerability, **CVE-2026-86296**, affecting its older **DIR-822A** dual-band Wi-Fi routers. This flaw, rated with maximum severity, is particularly concerning as public proof-of-concept (PoC) exploit code is already available, accelerating the potential for attackers to weaponize it.
### Unauthenticated Remote Code Execution Risk
**CVE-2026-86296** is a stack-based buffer overflow rooted in improper data handling within the **DIR-822A**'s DHCP server component. This vulnerability is highly dangerous because it can be exploited without any authentication or user interaction.
Attackers on the same local network can send specially crafted DHCP packets to the device. This triggers the buffer overflow, which could lead to a crash of the DHCP daemon or, more critically, enable remote code execution on the targeted router.
**D-Link** emphasized the severity of the flaw in its advisory, stating: "A specially crafted request may cause data to exceed the available stack buffer when processed by the strcpy function. Successful exploitation may cause memory corruption and could allow an attacker to affect the device's confidentiality, integrity, or availability."
### Second Critical Flaw Under Investigation
The company is also investigating a second critical vulnerability, **CVE-2026-86510**, also affecting **DIR-822A** routers. This out-of-bounds write flaw resides in the L2TP control message parser and was reported by the same security researcher who discovered **CVE-2026-86296**.
Similar to the first vulnerability, a public PoC exploit for **CVE-2026-86510** is also available. This flaw could allow threat actors with basic privileges to trigger arbitrary memory corruption by manipulating input data. Attacks would target devices configured to use L2TP or L2TPv6 WAN connectivity.
### Mitigation Strategies in Absence of Patches
While **D-Link** actively works on security patches for both vulnerabilities, it has advised customers to take immediate preventative measures. These include:
* Ensuring **DIR-822A** routers are not directly exposed to the internet.
* Restricting remote management access.
* Limiting administrative access to trusted systems and users through firewall rules or network-access controls.
### A History of Exploitation
Although **D-Link** has not yet confirmed these specific vulnerabilities are being exploited in the wild, the company's devices are frequently targeted. Vulnerable **D-Link** routers are often compromised and incorporated into large-scale botnets used for distributed denial-of-service (DDoS) attacks.
The **Cybersecurity and Infrastructure Security Agency (CISA)** currently tracks 26 **D-Link** security flaws that have been or are actively exploited, with two even abused by ransomware gangs. This history underscores the urgent need for users of the **DIR-822A** to implement the recommended mitigations promptly.