• Home Support Forums Security Advisories Shop     English | French
Support Announcement
(Non-US) DIR-822A – Stack-Based Buffer Overflow Vulnerability Reported
Overview
 
D-Link Systems, Inc. has become aware of a reported security vulnerability affecting the D-Link DIR-822A, identified as CVE-2026-86296.
 
The vulnerability affects the device's udhcpcd component and involves a stack-based buffer overflow associated with the use of the strcpy function in udhcpcd/serverpacket.c.
 
According to the published CVE information, the vulnerability may be exploited remotely without authentication or user interaction. A public proof-of-concept has also been reported.
 
The published CVE record identifies the affected product as:
 
Report 1:
  • Product: DIR-822A
  • Reported Version: A_101
  • Vulnerability Type: Stack-Based Buffer Overflow
  • Component: udhcpcd
  • Status: Under Investigation
 
Report 2:
  • Product: DIR-822A
  • Reported Version: A_101
  • Vulnerability Type: Out-of-Bounds Write
  • Component: function tunnel_set_params of the component L2TP Control Message Parser
  • Status: Under Investigation

 

 

D-Link is reviewing the reported vulnerability, affected product scope, and available remediation options.

 

Vulnerability Details

 

The reported issue involves improper handling of data within the udhcpcd component.

 

A specially crafted request may cause data to exceed the available stack buffer when processed by the strcpy function. Successful exploitation may cause memory corruption and could allow an attacker to affect the device’s confidentiality, integrity, or availability.

 

Technical Information

 

CV
CVE-2026-86296
 
Product
DIR-822A
 
Reported Version
A_101
 
Component
 
udhcpcd
 
Source File
 
udhcpcd/serverpacket.c
 
Function
 
strcpy
 
Vulnerability
Stack-Based Buffer Overflow
 
CWE
CWE-121 / CWE-119
 
Attack Vector
Network
 
Authentication Required
No
 
User Interaction Required
No
 
Public Proof-of-Concept
Reported
 
Status
Under Investigation
 
The CVE Numbering Authority has assigned the vulnerability a CVSS v3.1 score of 10.0 (Critical) and a CVSS v4.0 score of 10.0 (Critical).
 
The published CVSS v3.1 vector is: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R
 
CVE-2026-86510


Product

DIR-822A
Reported Version

A_101
Component

L2TP Control Message Parser
Function

tunnel_set_params
Vulnerability

Out-of-Bounds Write
CWE

CWE-787 / CWE-119
Attack Vector

Network
Attack Complexity

Low
Authentication / Privileges Required

Low Privileges Required
User Interaction Required

No
Public Proof-of-Concept

Reported
Status

Under Investigation

The CVE Numbering Authority has assigned the vulnerability a CVSS v3.1 score of 9.9 (Critical) and a CVSS v4.0 score of 9.4 (Critical). The published CVE record states that the issue affects the tunnel_set_params function within the L2TP Control Message Parser and may result in an out-of-bounds write. The issue can be triggered remotely, and a public exploit/Proof-of-Concept has been reported. (OpenCVE)

The published CVSS v3.1 vector is:

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R

The published CVSS v4.0 vector is:

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P (OpenCVE)

Affected Product

 

Model
Reported Version
Hardware Revision
Region
Security Update
DIR-822A
A_101
Under Confirmation
Under Confirmation
Under Investigation
 
The currently published vulnerability information identifies DIR-822A version A_101 as affected.
 
D-Link is continuing to verify:
 
  • the applicable hardware revision or revisions;
  • the geographic or regional product scope;
  • the product lifecycle status; and
  • whether an updated firmware release is available or appropriate.
 
We will update this announcement as additional verified information becomes available.
 
Recommended Customer Action
 
Customers using a DIR-822A should first verify the exact model, hardware revision, and installed firmware version of their device.
 
Until D-Link completes its investigation, customers should:
 
  • Ensure the device is not unnecessarily exposed to the public Internet.
  • Restrict remote management access unless required.
  • Use firewall or network-access controls to limit administrative access to trusted systems and users.
  • Monitor the applicable D-Link regional support site for updated firmware or product-security guidance.
  • Install only firmware specifically intended for the exact product model and hardware revision.
     
If D-Link determines that the affected product is no longer supported, D-Link will provide the appropriate product retirement and replacement guidance.
 

Hardware Revision and Firmware Notice

 
D-Link may manufacture products in multiple hardware revisions.
 
Firmware for one hardware revision may not be compatible with another revision of the same model.
 
Before installing firmware:
 
  • Confirm the complete product model.
  • Confirm the hardware revision shown on the product label.
  • Confirm the currently installed firmware version.
  • Download only firmware designated for that specific model and hardware revision.
  • Follow the installation instructions provided by the applicable D-Link support organization.
     
The hardware revision is normally printed on the product label near the serial number and may also be displayed in the device's web management interface.
 
Acknowledgment
 
D-Link acknowledges security researcher tian for the vulnerability report.
 
The vulnerability has been assigned:
 
  • CVE-2026-86296 – D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based buffer overflow
  • CVE Numbering Authority: VulDB
  • VulDB Reference: VDB-399458
 

References


  • CVE-2026-86296
  • VulDB VDB-399458