CVE-2026-86510
9.9D-Link · DIR-822A
An out-of-bounds write vulnerability exists in the L2TP Control Message Parser function tunnel_set_params of D-Link DIR-822A, allowing remote code execution via a specially crafted message.
Executive summary
A critical memory corruption vulnerability in D-Link DIR-822A routers enables remote attackers to achieve full system compromise.
Vulnerability
The flaw resides in the tunnel_set_params function within the L2TP Control Message Parser, which fails to correctly validate input, leading to an out-of-bounds write. While the vulnerability requires low privileges, its remote exploitability and impact on system memory make it highly dangerous.
Business impact
The CVSS score of 9.9 reflects the extreme severity of this vulnerability, as it allows for full confidentiality, integrity, and availability compromise of the affected device. Successful exploitation could result in complete network interception, unauthorized access to internal resources, or the use of the router as a persistent foothold for further attacks within the corporate or home network.
Remediation
Immediate Action: Check the official D-Link support portal for available firmware updates addressing this memory corruption issue. If no patch is currently provided, restrict access to the L2TP management interface immediately.
Proactive Monitoring: Monitor network traffic for unusual L2TP control packets and review device logs for signs of unauthorized configuration changes or unexpected reboots.
Compensating Controls: Deploy a network-level firewall or Intrusion Prevention System (IPS) to block suspicious L2TP traffic directed at the affected router until a vendor-supplied firmware fix is applied.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists, as documented in the researcher write-up at the provided Notion reference.
Analyst recommendation
Given the critical nature of this vulnerability and the availability of a public proof-of-concept, users must treat this as a high-priority incident. Administrators should prioritize the identification of affected hardware and apply vendor-provided updates as soon as they become available to prevent potential remote exploitation.
More D-Link CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section
Sources
Originally found and disclosed by tian (VulDB User), per the CVE Program record.
- VDB-399663 | D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write Vulnerability database entry
- VDB-399663 | CTI Indicators (IOB, IOC, IOA)
- CVE-2026-86510 | CVE Analysis and Report Third-party advisory
- Submit #906300 | D-Link DIR822A_101 A_101 Out-of-bounds Write Third-party advisory
- Exploit / PoC
- dlink.com