Skip to content
Tech News
← Back to articles

D-Link finds no fix for critical DIR-822A router flaw with public exploit code

read original get TP-Link Archer AX21 Wi-Fi 6 Router → more articles
GoKawiil Brief

D-Link disclosed a maximum-severity vulnerability, CVE-2026-86296, affecting its legacy DIR-822A dual-band routers, caused by a stack-based buffer overflow in the DHCP server component. The bug requires no authentication and can be triggered by sending crafted DHCP packets over the local network, potentially crashing the device or enabling remote code execution. A proof-of-concept exploit is already public, and D-Link has not yet released a patch. The company is also probing a second flaw, CVE-2026-86510, an out-of-bounds write in the L2TP parser reported by the same researcher.

Why It Matters

Because the DIR-822A is an older, widely deployed consumer router, any unpatched remote-code-execution flaw with public exploit code creates an easy target for botnets and network intrusions. The lack of authentication requirement and availability of proof-of-concept code significantly shortens the window before real-world attacks begin, especially since D-Link has no fix ready yet.

Key Takeaways
Worth a Look

TP-Link Archer AX21 Wi-Fi 6 Router — Since D-Link's legacy DIR-822A has an unpatched critical flaw, it's a good time to retire it for a router that's still receiving active security updates. The Archer AX21 offers modern Wi-Fi 6 performance and a currently supported firmware pipeline, giving you peace of mind against DHCP-based exploits like this one.

See TP-Link Archer AX21 Wi-Fi 6 Router on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

Source: bleepingcomputer.com, 2026-09-22

Published there as: “D-Link warns of max severity zero-day bug in DIR-822A routers”

Read the original report → The summary and analysis above are GoKawiil's own, written from reporting by the source above. Facts and quotes belong to the original publisher.