D-Link DIR-822A Router Hit by Two High-Severity Flaws, Patches Pending
D-Link has disclosed two critical vulnerabilities in its DIR-822A router running firmware A_101, assigned CVE-2026-86296 (CVSS 10.0) and CVE-2026-86510 (CVSS 9.9). The first flaw allows an unauthenticated attacker on the local network to trigger a stack-based buffer overflow via a crafted DHCP packet, while the second enables a low-privileged user to cause an out-of-bounds write through L2TP processing. Both vulnerabilities could lead to router crashes, memory corruption, or potential loss of confidentiality and integrity. Public proof-of-concept code exists for both flaws, though real-world exploitation and stable code execution have not yet been confirmed. D-Link is investigating the scope and developing firmware fixes, urging users in the meantime to restrict remote access, block untrusted local devices, and disable L2TP/L2TPv6 WAN connectivity if not needed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in