<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1" -->

---
title: D-Link warns of max severity zero-day bug in DIR-822A...
description: D-Link has warned customers about a maximum-severity zero-day vulnerability (CVE-2026-86296) in legacy DIR-822A dual-band Wi-Fi routers, with public...
canonical: https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: D-Link warns of max severity zero-day bug in DIR-822A routers | daily.dev
og:description: D-Link has warned customers about a maximum-severity zero-day vulnerability (CVE-2026-86296) in legacy DIR-822A dual-band Wi-Fi routers, with public...
og:url: https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1
og:image: https://api.daily.dev/og/posts/Qt5pbASG1.png
og:image:alt: D-Link warns of max severity zero-day bug in DIR-822A routers
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# D-Link warns of max severity zero-day bug in DIR-822A routers

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 3 min read · 0 upvotes · 0 comments

## Summary

D-Link has warned customers about a maximum-severity zero-day vulnerability (CVE-2026-86296) in legacy DIR-822A dual-band Wi-Fi routers, with public proof-of-concept exploit code already available and no patch yet issued. The flaw is a stack-based buffer overflow in the DHCP server's udhcpd component, triggered via crafted DHCP packets without authentication, potentially allowing remote code execution. D-Link is also investigating a second critical flaw, CVE-2026-86510, an out-of-bounds write in the L2TP control message parser, also with public PoC code. Neither vulnerability is confirmed as actively exploited yet, but D-Link devices are historically popular botnet targets, and CISA tracks 26 D-Link flaws exploited in the wild. Affected users are advised to avoid exposing routers online and restrict remote management access until patches are released.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers>

## Questions this post answers

### What is CVE-2026-86296 and does it affect my D-Link DIR-822A router?

CVE-2026-86296 is a maximum-severity stack-based buffer overflow in the udhcpd DHCP server component of D-Link DIR-822A routers, caused by improper handling of DHCP packet data in the strcpy function. It can be exploited remotely without authentication or user interaction, potentially crashing the DHCP daemon or enabling remote code execution. No patch exists yet, and a public proof-of-concept exploit has been released.

_daily.dev surfaces vulnerability disclosures like this so network admins can act before exploits go public._

### Is there a second unpatched vulnerability in D-Link DIR-822A routers besides the DHCP flaw?

Yes, D-Link is investigating CVE-2026-86510, a critical out-of-bounds write vulnerability in the L2TP control message parser affecting DIR-822A routers configured for L2TP or L2TPv6 WAN connectivity. Attackers with basic privileges could manipulate input data to corrupt memory. Public proof-of-concept exploit code exists for this flaw too, reported by the same researcher who found the DHCP bug.

_Tracking multiple concurrent CVEs against the same device is easier when relevant security advisories land on daily.dev._

### How can I protect my D-Link DIR-822A router until a patch is released?

D-Link recommends ensuring DIR-822A routers are not exposed directly to the internet, restricting remote management access, and limiting administrative access to trusted systems and users through firewall or network-access controls. No official patch exists yet for either the DHCP buffer overflow (CVE-2026-86296) or the L2TP out-of-bounds write (CVE-2026-86510) flaws.

_Mitigating exposed legacy routers stays manageable when developers follow security advisories on daily.dev._

## Similar posts on daily.dev

- [New Mirai campaign exploits RCE flaw in EoL D-Link routers](https://daily.dev/posts/new-mirai-campaign-exploits-rce-flaw-in-eol-d-link-routers-trf2b9hdd) · BleepingComputer · 0 upvotes · 0 comments
- [AryStinger botnet infected thousands of D-Link routers worldwide](https://daily.dev/posts/arystinger-botnet-infected-thousands-of-d-link-routers-worldwide-9f0wocue1) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"D-Link warns of max severity zero-day bug in DIR-822A routers","url":"https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1"},"datePublished":"2026-09-22T12:52:46.786Z","dateModified":"2026-09-22T14:50:32.407Z","description":"D-Link has warned customers about a maximum-severity zero-day vulnerability (CVE-2026-86296) in legacy DIR-822A dual-band Wi-Fi routers, with public...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/27b48dc33fb6f237caf611df2947dc92?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/27b48dc33fb6f237caf611df2947dc92?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security","timeRequired":"PT3M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"D-Link warns of max severity zero-day bug in DIR-822A routers"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers-qt5pbasg1#faq","mainEntity":[{"@type":"Question","name":"What is CVE-2026-86296 and does it affect my D-Link DIR-822A router?","acceptedAnswer":{"@type":"Answer","text":"CVE-2026-86296 is a maximum-severity stack-based buffer overflow in the udhcpd DHCP server component of D-Link DIR-822A routers, caused by improper handling of DHCP packet data in the strcpy function. It can be exploited remotely without authentication or user interaction, potentially crashing the DHCP daemon or enabling remote code execution. No patch exists yet, and a public proof-of-concept exploit has been released. daily.dev surfaces vulnerability disclosures like this so network admins can act before exploits go public."}},{"@type":"Question","name":"Is there a second unpatched vulnerability in D-Link DIR-822A routers besides the DHCP flaw?","acceptedAnswer":{"@type":"Answer","text":"Yes, D-Link is investigating CVE-2026-86510, a critical out-of-bounds write vulnerability in the L2TP control message parser affecting DIR-822A routers configured for L2TP or L2TPv6 WAN connectivity. Attackers with basic privileges could manipulate input data to corrupt memory. Public proof-of-concept exploit code exists for this flaw too, reported by the same researcher who found the DHCP bug. Tracking multiple concurrent CVEs against the same device is easier when relevant security advisories land on daily.dev."}},{"@type":"Question","name":"How can I protect my D-Link DIR-822A router until a patch is released?","acceptedAnswer":{"@type":"Answer","text":"D-Link recommends ensuring DIR-822A routers are not exposed directly to the internet, restricting remote management access, and limiting administrative access to trusted systems and users through firewall or network-access controls. No official patch exists yet for either the DHCP buffer overflow (CVE-2026-86296) or the L2TP out-of-bounds write (CVE-2026-86510) flaws. Mitigating exposed legacy routers stays manageable when developers follow security advisories on daily.dev."}}]}
```

