CVE-2026-86296
Summary
A maximum-severity stack-based buffer overflow in the DHCP server component of legacy D-Link DIR-822A dual-band Wi-Fi routers, disclosed with public proof-of-concept exploit code and no patch.
Details
The flaw is a stack-based buffer overflow and improper data handling in the DHCP server component, reachable without authentication or user interaction by an attacker on the same local network who sends a crafted DHCP packet; D-Link states a specially crafted request can exceed the available stack buffer when processed by strcpy in udhcpcd/serverpacket.c, causing memory corruption and potentially remote code execution. D-Link published the advisory on 18 September 2026 and the reporting researcher released a proof of concept, which the vendor warns may accelerate weaponisation.
Defensive guidance
No patch existed at disclosure. D-Link's guidance is to keep DIR-822A routers off the public internet, restrict remote management, and limit administrative access to trusted systems via firewall or network-access controls. D-Link is also investigating a second flaw reported by the same researcher, CVE-2026-86510, a critical out-of-bounds write in the L2TP control-message parser affecting devices configured for L2TP or L2TPv6 WAN connectivity; that flaw also has public proof-of-concept code.
Australian Significance
Legacy consumer and small-business routers are a standing botnet-recruitment pool: CISA tracks 26 D-Link flaws that have been or are still exploited, two of them abused by ransomware gangs. For Australian small and medium businesses — the audience the ACSC addresses directly — the practical control is replacement or isolation of end-of-support hardware rather than patch management, because none is coming.
Related Pages
Sources: raw/digests/Cyber-Digest-2026-09-23.md