Overview
D-Link Systems, Inc. has become aware of a reported security vulnerability affecting the D-Link DIR-822A, identified as CVE-2026-86296.
The vulnerability affects the device's udhcpcd component and involves a stack-based buffer overflow associated with the use of the strcpy function in udhcpcd/serverpacket.c.
According to the published CVE information, the vulnerability may be exploited remotely without authentication or user interaction. A public proof-of-concept has also been reported.
The published CVE record identifies the affected product as:
D-Link is reviewing the reported vulnerability, affected product scope, and available remediation options.
Vulnerability Details
The reported issue involves improper handling of data within the udhcpcd component.
A specially crafted request may cause data to exceed the available stack buffer when processed by the strcpy function. Successful exploitation may cause memory corruption and could allow an attacker to affect the device’s confidentiality, integrity, or availability.
Technical Information
|
CV
|
CVE-2026-86296
|
|
Product
|
DIR-822A
|
|
Reported Version
|
A_101
|
|
Component
|
udhcpcd
|
|
Source File
|
udhcpcd/serverpacket.c
|
|
Function
|
strcpy
|
|
Vulnerability
|
Stack-Based Buffer Overflow
|
|
CWE
|
CWE-121 / CWE-119
|
|
Attack Vector
|
Network
|
|
Authentication Required
|
No
|
|
User Interaction Required
|
No
|
|
Public Proof-of-Concept
|
Reported
|
|
Status
|
Under Investigation
|
The CVE Numbering Authority has assigned the vulnerability a CVSS v3.1 score of 10.0 (Critical) and a CVSS v4.0 score of 10.0 (Critical).
The published CVSS v3.1 vector is: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R
Affected Product
|
Model
|
Reported Version
|
Hardware Revision
|
Region
|
Security Update
|
|
DIR-822A
|
A_101
|
Under Confirmation
|
Under Confirmation
|
Under Investigation
|
The currently published vulnerability information identifies DIR-822A version A_101 as affected.
D-Link is continuing to verify:
-
the applicable hardware revision or revisions;
-
the geographic or regional product scope;
-
the product lifecycle status; and
-
whether an updated firmware release is available or appropriate.
We will update this announcement as additional verified information becomes available.
Recommended Customer Action
Customers using a DIR-822A should first verify the exact model, hardware revision, and installed firmware version of their device.
Until D-Link completes its investigation, customers should:
-
Ensure the device is not unnecessarily exposed to the public Internet.
-
Restrict remote management access unless required.
-
Use firewall or network-access controls to limit administrative access to trusted systems and users.
-
Monitor the applicable D-Link regional support site for updated firmware or product-security guidance.
-
Install only firmware specifically intended for the exact product model and hardware revision.
If D-Link determines that the affected product is no longer supported, D-Link will provide the appropriate product retirement and replacement guidance.
Hardware Revision and Firmware Notice
D-Link may manufacture products in multiple hardware revisions.
Firmware for one hardware revision may not be compatible with another revision of the same model.
Before installing firmware:
-
Confirm the complete product model.
-
Confirm the hardware revision shown on the product label.
-
Confirm the currently installed firmware version.
-
Download only firmware designated for that specific model and hardware revision.
-
Follow the installation instructions provided by the applicable D-Link support organization.
The hardware revision is normally printed on the product label near the serial number and may also be displayed in the device's web management interface.
Acknowledgment
D-Link acknowledges security researcher tian for the vulnerability report.
The vulnerability has been assigned:
-
CVE-2026-86296 – D-Link DIR-822A udhcpcd serverpacket.c strcpy stack-based buffer overflow
-
CVE Numbering Authority: VulDB
-
VulDB Reference: VDB-399458
References
-
CVE-2026-86296
-
VulDB VDB-399458