CVE-2026-86296

10.0

D-Link · DIR-822A

A stack-based buffer overflow in D-Link DIR-822A allows unauthenticated remote attackers to execute arbitrary code via the udhcpcd component.

Executive summary

A critical stack-based buffer overflow in the D-Link DIR-822A router enables unauthenticated remote code execution, posing an immediate risk of full device compromise.

Vulnerability

The vulnerability exists in the strcpy function within the udhcpcd/serverpacket.c file of the udhcpcd component. This memory corruption flaw allows an unauthenticated remote attacker to trigger a stack-based buffer overflow, potentially leading to arbitrary code execution.

Business impact

The CVSS score of 10.0 reflects the maximum severity level, indicating that this vulnerability is highly exploitable and allows for complete system compromise. Successful exploitation could grant an attacker full control over the network device, leading to unauthorized access to internal network traffic, data exfiltration, or the use of the device as a pivot point for further lateral movement within the organization.

Remediation

Immediate Action: Since a specific patch version is not currently identified, users should restrict access to the affected device management interfaces from the public internet immediately.

Proactive Monitoring: Monitor network traffic for anomalous behavior or unexpected crashes related to the DHCP server process on the device.

Compensating Controls: If the device must remain online, utilize a firewall to restrict access to the affected service to trusted IP addresses only and disable unnecessary external-facing features.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical write-up provided in the vulnerability references.

Analyst recommendation

This vulnerability is critical and requires immediate attention due to the ease of remote exploitation and the lack of required authentication. Organizations using the D-Link DIR-822A should prioritize isolating these devices from external networks until the vendor releases a formal firmware update to address the buffer overflow. Persistent monitoring of the device logs is essential to detect any signs of attempted exploitation.

More D-Link CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by tian (VulDB User), per the CVE Program record.