FR
live
tag

#dir-822a

D-Link confirms two critical, unpatched flaws in the DIR-822A router, with public exploits

On September 22, 2026, D-Link confirmed two critical flaws in the end-of-life DIR-822A router: a stack-based buffer overflow in the DHCP server (CVE-2026-86296, CVSS 10) and an out-of-bounds write in the L2TP parser (CVE-2026-86510, CVSS 9.9), both with public proof-of-concept code and no patch available. Replace or isolate these routers, and never expose them to the internet.

Type at least two characters.

navigate open esc dismiss