CVE-2026-86296
10.0D-Link · DIR-822A
A stack-based buffer overflow in D-Link DIR-822A allows unauthenticated remote attackers to execute arbitrary code via the udhcpcd component.
Executive summary
A critical stack-based buffer overflow in the D-Link DIR-822A router enables unauthenticated remote code execution, posing an immediate risk of full device compromise.
Vulnerability
The vulnerability exists in the strcpy function within the udhcpcd/serverpacket.c file of the udhcpcd component. This memory corruption flaw allows an unauthenticated remote attacker to trigger a stack-based buffer overflow, potentially leading to arbitrary code execution.
Business impact
The CVSS score of 10.0 reflects the maximum severity level, indicating that this vulnerability is highly exploitable and allows for complete system compromise. Successful exploitation could grant an attacker full control over the network device, leading to unauthorized access to internal network traffic, data exfiltration, or the use of the device as a pivot point for further lateral movement within the organization.
Remediation
Immediate Action: Since a specific patch version is not currently identified, users should restrict access to the affected device management interfaces from the public internet immediately.
Proactive Monitoring: Monitor network traffic for anomalous behavior or unexpected crashes related to the DHCP server process on the device.
Compensating Controls: If the device must remain online, utilize a firewall to restrict access to the affected service to trusted IP addresses only and disable unnecessary external-facing features.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists and is attributed to the technical write-up provided in the vulnerability references.
Analyst recommendation
This vulnerability is critical and requires immediate attention due to the ease of remote exploitation and the lack of required authentication. Organizations using the D-Link DIR-822A should prioritize isolating these devices from external networks until the vendor releases a formal firmware update to address the buffer overflow. Persistent monitoring of the device logs is essential to detect any signs of attempted exploitation.
More D-Link CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by tian (VulDB User), per the CVE Program record.
- VDB-399458 | D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based overflow Vulnerability database entry
- VDB-399458 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-86296 | CVE Analysis and Report Third-party advisory
- Submit #906297 | D-Link DIR822A_101 A_101 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com