D-Link finds no fix for critical DIR-822A router flaw with public exploit code
D-Link disclosed a maximum-severity vulnerability, CVE-2026-86296, affecting its legacy DIR-822A dual-band routers, caused by a stack-based buffer overflow in the DHCP server component. The bug requires no authentication and can be triggered by sending crafted DHCP packets over the local network, potentially crashing the device or enabling remote code execution. A proof-of-concept exploit is already public, and D-Link has not yet released a patch. The company is also probing a second flaw, CVE-2026-86510, an out-of-bounds write in the L2TP parser reported by the same researcher.