CVE-2026-86509

9.6

D-Link · DIR-895L

A stack-based buffer overflow exists in the udhcpd component of D-Link DIR-895L firmware A1_102b07 due to improper handling of DHCP packets in the sendOffer/sendACK functions.

Executive summary

A critical stack-based buffer overflow vulnerability in D-Link DIR-895L firmware allows unauthenticated local network attackers to achieve remote code execution and full system compromise.

Vulnerability

This is a stack-based buffer overflow (CWE-121) triggered by the processing of malformed packets within the udhcpcd component's sendOffer and sendACK functions. The vulnerability is exploitable by an unauthenticated attacker located on the local network.

Business impact

The CVSS score of 9.6 reflects the severe potential for full system compromise, including the ability to execute arbitrary code with elevated privileges. Successful exploitation could lead to complete loss of network control, interception of traffic, and the potential for lateral movement into the internal network, posing a significant risk to organizational data confidentiality and operational integrity.

Remediation

Immediate Action: Since a specific patch version is currently unknown, verify if your device firmware is version A1_102b07 and restrict access to the affected service if possible, or transition to a supported hardware platform.

Proactive Monitoring: Monitor network traffic for anomalous DHCP traffic patterns or unexpected crashes of the udhcpd service, which may indicate exploitation attempts.

Compensating Controls: Implement network segmentation to isolate the affected D-Link devices and utilize internal firewalls to block unauthorized traffic destined for the management or DHCP services of the router.

Exploitation status

Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the researcher write-up provided in the referenced technical analysis.

Analyst recommendation

Given the critical nature of this buffer overflow and the availability of public exploitation details, security teams must treat this vulnerability with high priority. If the vendor has not provided a firmware update, administrators should isolate affected hardware from sensitive network segments immediately to prevent unauthorized access and potential code execution.

More D-Link CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources

Originally found and disclosed by tian (VulDB User), per the CVE Program record.