D-Link Expands Alert to Two Critical DIR-822A Router Flaws
D-Link is investigating two critical vulnerabilities in the DIR-822A router running firmware A_101. A publicly reported PoC exists for one of them, while a fix has not yet been confirmed.

D-Link DIR-822A vulnerabilities In an updated security announcement, D-Link expanded its information about DIR-822A router vulnerabilities to include a second critical flaw. D-Link says it is investigating CVE-2026-86296 and CVE-2026-86510 in the DIR-822A router running firmware version A_101. A proof of concept (PoC) has been publicly reported for the first flaw, while the availability of a security update remains unresolved.
D-Link DIR-822A vulnerabilities include a CVSS 10.0 flaw
CVE-2026-86296 is a stack-based buffer overflow in the udhcpcd component. According to the CVE record, it is a network-exploitable flaw that requires neither authentication nor user interaction. The CNA assigned it the maximum score of 10.0 under both CVSS v3.1 and CVSS v4.0.
A PoC, or a demonstration of a technical procedure for demonstrating the vulnerability, has also been publicly reported. This alone does not confirm attacks in real-world environments. Neither D-Link nor the available information confirms active exploitation of CVE-2026-86296.
In its updated notice, the manufacturer added CVE-2026-86510. This is a critical out-of-bounds write flaw in the L2TP control-message parser, which likewise affects the reported A_101 version. The fact sheet does not provide details about the practical exploitation of the second flaw.
Neither a fix nor the exact scope has been confirmed
D-Link says the investigation is ongoing. It has not been confirmed which hardware revisions of the DIR-822A router and which regional variants are affected. It also remains unclear whether the manufacturer will release new firmware.
Until the scope is clarified, D-Link recommends not exposing the device directly to the internet, restricting remote administration, and using network filters. According to the available information, the highest risk concerns routers whose remote administration is accessible from the public internet.
- Check the device model, hardware revision, and firmware version.
- Disable remote administration if you do not need it.
- Do not expose the router’s administration interface directly to the internet.
- Monitor D-Link security announcements for the availability of a fix or additional measures.
DIR-822 model support context
For the U.S. model DIR-822-US, D-Link previously announced that support would end on March 29, 2024. However, the current security announcement concerns the DIR-822A, and the manufacturer is still verifying the specific hardware revisions and regional scope. Therefore, information about the end of support for the DIR-822-US model cannot automatically be equated with every device labeled DIR-822A.
The zero-day designation for CVE-2026-86296 should in this case be understood as a publicly known flaw without a confirmed fix. It does not automatically mean that the vulnerability is actively being used by attackers. Other important information will include confirmation of the affected versions and regions, any firmware release, and any credible reports of exploitation.
Sources
- D-Link Security Announcement SAP10516 – Confirms the CVE-2026-86296 and CVE-2026-86510 vulnerabilities, the investigation status, the publicly reported PoC, the unverified scope, and the recommended mitigations.
- CVE Record for CVE-2026-86296 – Confirms the published CVE record, the affected A_101 version, the CVSS rating, and the existence of a publicly disclosed exploit/PoC.
- D-Link DIR-822-US End of Support Notice – Confirms the end of support for the U.S. DIR-822-US model on March 29, 2024.
Verified and updated: September 22, 2026 15:27



