Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve, zero-day, iot] · confidence: high · severity: critical · affected_sectors: [technology, retail] · au_impact: true

CVE-2026-86296

Summary

A maximum-severity stack-based buffer overflow in the DHCP server component of legacy D-Link DIR-822A dual-band Wi-Fi routers, disclosed with public proof-of-concept exploit code and no patch.

Details

The flaw is a stack-based buffer overflow and improper data handling in the DHCP server component, reachable without authentication or user interaction by an attacker on the same local network who sends a crafted DHCP packet; D-Link states a specially crafted request can exceed the available stack buffer when processed by strcpy in udhcpcd/serverpacket.c, causing memory corruption and potentially remote code execution. D-Link published the advisory on 18 September 2026 and the reporting researcher released a proof of concept, which the vendor warns may accelerate weaponisation.

Defensive guidance

No patch existed at disclosure. D-Link's guidance is to keep DIR-822A routers off the public internet, restrict remote management, and limit administrative access to trusted systems via firewall or network-access controls. D-Link is also investigating a second flaw reported by the same researcher, CVE-2026-86510, a critical out-of-bounds write in the L2TP control-message parser affecting devices configured for L2TP or L2TPv6 WAN connectivity; that flaw also has public proof-of-concept code.

Australian Significance

Legacy consumer and small-business routers are a standing botnet-recruitment pool: CISA tracks 26 D-Link flaws that have been or are still exploited, two of them abused by ransomware gangs. For Australian small and medium businesses — the audience the ACSC addresses directly — the practical control is replacement or isolation of end-of-support hardware rather than patch management, because none is coming.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-09-23.md