D-Link Warns of High-Risk Vulnerabilities in DIR-822A Routers, Urges Customers to Take Immediate Action
D-Link has issued a critical warning about two serious security flaws affecting its legacy DIR-822A dual-band Wi-Fi routers. The vulnerabilities, discovered by a security researcher who has published proof-of-concept exploit code, can be exploited remotely without any authentication or user interaction. This means that attackers can potentially crash the device’s DHCP daemon or execute malicious code on targeted devices.
The first vulnerability, identified as CVE-2026-86296, is a stack-based buffer overflow caused by improper data handling in the DHCP server component. When an attacker sends a specially crafted DHCP packet to the device, it can trigger the overflow and cause memory corruption. This could allow attackers to compromise the device’s confidentiality, integrity, or availability.
The second vulnerability, identified as CVE-2026-86510, is a critical out-of-bounds write in the L2TP control message parser. An attacker with basic privileges can exploit this flaw by manipulating input data to cause an out-of-bounds write in attacks targeting devices configured to use L2TP or L2TPv6 WAN connectivity.
D-Link has advised customers to take immediate action to protect their DIR-822A routers. The company recommends that users ensure their devices are not exposed online, restrict remote management access, and limit administrative access to trusted systems and users via firewall or network-access controls. This is crucial because threat actors often target vulnerable D-Link devices, infect them with malware, and add them to large-scale botnets used for distributed denial-of-service (DDoS) attacks.
The Cybersecurity and Infrastructure Security Agency (CISA) tracks 26 D-Link security flaws that have been or are still exploited in attacks. This highlights the importance of staying vigilant and keeping devices up-to-date with the latest security patches. In this case, however, D-Link has not yet released a patch for these vulnerabilities, making it even more critical for users to take action to protect their devices.
As the threat landscape continues to evolve, it’s essential for device manufacturers like D-Link to prioritize security and disclose vulnerabilities promptly. This allows customers to take proactive steps to mitigate risks and prevent potential attacks. In this case, D-Link’s swift warning has given customers a critical head start in securing their DIR-822A routers.
To stay safe, users should regularly review their network settings, ensure all devices are up-to-date with the latest security patches, and implement robust access controls to limit administrative privileges. By taking these precautions, you can significantly reduce the risk of your device being compromised by attackers exploiting these high-risk vulnerabilities.
Source: Bleeping Computer — 2026-09-22