Two Critical Bugs, One Router: What the D-Link DIR-822A Disclosures Mean for Home Networks
Vulnerability overview
Two memory-safety defects were disclosed in the D-Link DIR-822A router on the same day, and they
are easy to confuse. CVE-2026-86296 is a stack buffer overflow in the DHCP server, rated 10.0.
CVE-2026-86510 is an out-of-bounds write in the L2TP control message parser, rated 9.9. Both affect
firmware A_101, and both were published with functional proof-of-concept code.
This article focuses on CVE-2026-86510, but the two bugs share enough context that treating them
separately would misrepresent the risk.
Mechanism and exploitation conditions
CVE-2026-86510 lives in tunnel_set_params, the function that applies parameters from an L2TP
control message. The parser copies attacker-supplied fields into a fixed-size structure without
validating length, so an oversized message writes past the end of its destination.
The companion bug, CVE-2026-86296, is a different animal. It sits in the DHCP server's TR-111
option 125 parsing path, where length-delimited binary subfields are treated as null-terminated C
strings and copied into 256-byte stack buffers with strcpy. The result is a classic stack
overflow reachable from unauthenticated DHCP traffic on the local network.
Both require the attacker to reach the device's local network. Neither is described as exploitable
from the public internet without that foothold.
Impact
The DHCP flaw is the more dangerous of the two on paper, and not only because of its score. DHCP
traffic is unauthenticated by design, so any host on the LAN can send the triggering packet without
credentials. The L2TP flaw needs the attacker to reach the L2TP daemon, which is a narrower
condition but still realistic on a flat home or small-office network.
Either bug can crash the device. Either can, depending on build and memory layout, lead to code
execution. On a router, code execution means the attacker can observe and modify traffic, and can
use the device as a foothold for the rest of the network.
Affected products and scope
The confirmed scope is the D-Link DIR-822A running firmware A_101. D-Link has said it is reviewing
the report, the affected product scope, and remediation options. Until that review concludes,
assume the confirmed scope is the only scope you can rely on, and treat the absence of a statement
about other models as an absence of information rather than a clean bill of health.
Exposure context
ZoomEye returned 624 assets for the model title query title="DIR-822" and 6,697,454 assets for the broader vendor fingerprint app="D-Link". The vendor-wide number says nothing about which firmware is installed, so the model-specific count is the figure worth quoting. Even that number only proves that DIR-822 family devices are reachable from the internet or a scanned network; it does not prove that any of them are exploitable.
Remediation and mitigations
No fixed firmware exists yet. Until one does:
- Put the router behind a network you control and keep untrusted devices off the same segment.
- Turn off WAN-side remote management.
- Segment guest Wi-Fi from the administration interface.
- Track D-Link's advisory page and be prepared to replace the device if no patch arrives.
References
- D-Link DIR-822A Vulnerabilities Details and PoC Disclosed — https://securityonline.info/d-link-dir-822a-vulnerabilities-poc/
- CVE-2026-86510 — https://www.cve.org/CVERecord?id=CVE-2026-86510
- CVE-2026-86296 — https://www.cve.org/CVERecord?id=CVE-2026-86296
Top comments (1)
On the detection side, the DHCP one is the cheaper to cover while there is no patch: because length-delimited subfields are parsed as C strings, a passive LAN tap that alerts on TR-111 option 125 payloads longer than 256 bytes catches the trigger without touching the router. For the L2TP side, most home routers never legitimately speak L2TP at all, so control-channel messages arriving from hosts that never terminate a tunnel are themselves the signal worth alerting on.