CVE-2026-86510
Summary
A critical out-of-bounds write in the L2TP control message parser of legacy D-Link DIR-822A routers, reported with public proof-of-concept code and still under investigation.
Details
A critical out-of-bounds write in the L2TP control-message parser of D-Link DIR-822A routers, reported by the same researcher who disclosed CVE-2026-86296 and published with public proof-of-concept code. D-Link states an attacker with basic privileges may trigger arbitrary memory corruption by manipulating input data, in attacks targeting devices configured to use L2TP or L2TPv6 WAN connectivity.
Defensive guidance
D-Link was still investigating at the time of its advisory and no patch was available. Mitigation is configuration-based: do not expose the router to the internet, restrict remote management, and limit administrative access to trusted systems through firewall or network-access controls.
Australian Significance
The two DIR-822A flaws compound rather than duplicate each other — a LAN-side overflow in the DHCP daemon and a WAN-side parser write — so a device that survives one exposure path remains reachable through the other. As with CVE-2026-86296, the realistic Australian small-business control is retirement of end-of-support hardware.
Related Pages
Sources: raw/digests/Cyber-Digest-2026-09-23.md