D-Link Warns of Maximum-Security Flaw in DIR-822A Routers, Exposing Millions to Remote Attacks
D-Link has issued a critical warning about a maximum-severity vulnerability affecting its legacy DIR-822A dual-band Wi-Fi routers. The security flaw, identified as CVE-2026-86296, can be exploited without authentication or user interaction, allowing attackers to potentially crash the device’s DHCP daemon or execute malicious code on targeted devices.
The vulnerability stems from a stack-based buffer overflow and improper data handling in the DHCP server component of the DIR-822A routers. This means that attackers can send specially crafted DHCP packets to the device, triggering the overflow and compromising its security. D-Link has confirmed that the issue affects all versions of the DIR-822A router firmware.
The severity of this vulnerability is underscored by the fact that a security researcher who discovered the issue has already published public proof-of-concept (PoC) exploit code. This means that attackers may be able to weaponize the flaw in real-world attacks, making it essential for D-Link customers to take immediate action to secure their devices.
D-Link is also investigating another vulnerability affecting its DIR-822A routers, a critical out-of-bounds write (CVE-2026-86510) in the L2TP control message parser. This flaw can be exploited by attackers with basic privileges, allowing them to trigger arbitrary memory corruption and compromise device security.
To mitigate these risks, D-Link has advised customers to ensure their DIR-822A routers are not exposed online, restrict remote management access, and limit administrative access to trusted systems and users via firewall or network-access controls. However, given the maximum-severity classification of this vulnerability and the potential for exploitation, it’s essential that all affected parties take proactive steps to secure their devices.
The impact of these vulnerabilities is far-reaching, as D-Link devices are often targeted by attackers in large-scale botnets used for distributed denial-of-service (DDoS) attacks. In fact, the Cybersecurity and Infrastructure Security Agency (CISA) tracks 26 D-Link security flaws that have been or are still exploited in attacks.
To protect yourself from this vulnerability, it’s essential to take immediate action:
* Ensure your DIR-822A router is not exposed online.
* Restrict remote management access using firewall or network-access controls.
* Limit administrative access to trusted systems and users.
* Stay informed about the latest security updates and patches for your device.
Remember, a proactive approach to security is key. By taking these steps, you can minimize the risk of exploitation and ensure the continued security and integrity of your DIR-822A router.
Source: Bleeping Computer — 2026-09-22