Vulnerability
Published 2026-09-18
Verified 2026-09-22

D-Link DIR-822A CVE-2026-86296 (CVSS 10.0) unauth remote stack overflow in udhcpcd; companion CVE-2026-86510 (9.9) — under investigation

D-Link Security Announcement SAP10516 (published 18 September 2026; last updated 21 September 2026) confirms it is investigating two critical flaws reported against DIR-822A firmware A_101. CVE-2026-86296 is a stack-based buffer overflow in udhcpcd (strcpy in udhcpcd/serverpacket.c): network-reachable, no authentication, no user interaction; CNA/VulDB publish CVSS 3.1 10.0 Critical (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) and CVSS 4.0 10.0; a public proof-of-concept is reported. Companion CVE-2026-86510 is an out-of-bounds write in L2TP Control Message Parser tunnel_set_params (CVSS 3.1 9.9 / CVSS 4.0 9.4 per vendor write-up); low privileges, no user interaction. Both statuses: Under Investigation — D-Link has not yet confirmed full hardware-revision scope or a remediation build. Primary: D-Link SAP10516; CVE metadata: CVE.report / VulDB; wire: Cyber Security News 22 Sep 2026.

Product
D-Link DIR-822A (reported firmware A_101); udhcpcd + L2TP Control Message Parser
Versions
Reported affected: DIR-822A firmware A_101 (per SAP10516 / CVE). Full hardware-revision and regional scope still under investigation; no fixed build listed on SAP10516 as of 21 Sep 2026 update.
CVSS
(CVSS 3.1 Critical; CNA) / 10.0 (CVSS 4.0 Critical); companion CVE-2026-86510 9.9 (CVSS 3.1) / 9.4 (CVSS 4.0)
Exploited in Australia?
unknown
Patch to
Inventory internet-facing DIR-822A; remove WAN exposure of management/DHCP/L2TP services; watch D-Link SAP10516 for firmware remediation; replace EOL/unpatched units if no fix is issued; treat public PoC as elevated risk for exposed CPE

Primary: D-Link SAP10516 — DIR-822A CVE-2026-86296 / CVE-2026-86510 (18–21 Sep 2026) · Vendor: D-Link Technical Support — Security Announcement SAP10516 · CVE: CVE-2026-86296, CVE-2026-86510 · CVE.report — CVE-2026-86296; also VulDB VDB-399458; CSN 22 Sep

vulnerabilities network