Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve, zero-day, iot] · confidence: high · severity: critical · affected_sectors: [technology, retail] · au_impact: true

CVE-2026-86510

Summary

A critical out-of-bounds write in the L2TP control message parser of legacy D-Link DIR-822A routers, reported with public proof-of-concept code and still under investigation.

Details

A critical out-of-bounds write in the L2TP control-message parser of D-Link DIR-822A routers, reported by the same researcher who disclosed CVE-2026-86296 and published with public proof-of-concept code. D-Link states an attacker with basic privileges may trigger arbitrary memory corruption by manipulating input data, in attacks targeting devices configured to use L2TP or L2TPv6 WAN connectivity.

Defensive guidance

D-Link was still investigating at the time of its advisory and no patch was available. Mitigation is configuration-based: do not expose the router to the internet, restrict remote management, and limit administrative access to trusted systems through firewall or network-access controls.

Australian Significance

The two DIR-822A flaws compound rather than duplicate each other — a LAN-side overflow in the DHCP daemon and a WAN-side parser write — so a device that survives one exposure path remains reachable through the other. As with CVE-2026-86296, the realistic Australian small-business control is retirement of end-of-support hardware.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-09-23.md