Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Perenco on offshore platform electrification quest to power Brazil’s shallow-water fields from shore

    September 23, 2026

    Federal immigration policy may be worsening Wisconsin’s caregiver shortage, leaders say

    September 23, 2026

    Trump-Xi Summit: What to Expect on AI, Trade, Critical Minerals

    September 23, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Perenco on offshore platform electrification quest to power Brazil’s shallow-water fields from shore
    • Federal immigration policy may be worsening Wisconsin’s caregiver shortage, leaders say
    • Trump-Xi Summit: What to Expect on AI, Trade, Critical Minerals
    • Video of protests in Greece isn’t recent
    • When climate mitigation becomes politicised: The Guardian uncovers IPCC links to Saudi oil industry – Spotlight
    • Eight Sleep’s new cooling hub is small enough to hide under your bed
    • Microsoft: September Windows updates break Always On VPN connections
    • Live updates: Bitcoin slips under $86,000 as money rotates into BCH and ZEC
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, September 23
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    D-Link warns of max severity zero-day bug in DIR-822A routers

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 23, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.

    This security flaw stems from a stack-based buffer overflow and improper data handling in the DHCP server component and can be exploited without authentication or user interaction.

    Attackers without valid credentials on the same local network can send crafted DHCP packets to the device, trigger the overflow, and potentially crash the DHCP daemon or achieve remote code execution on targeted devices.

    D-Link also warned that the security researcher who found and reported the issue published a proof-of-concept (PoC) exploit, which may allow attackers to weaponize the vulnerability in the wild faster.

    “A specially crafted request may cause data to exceed the available stack buffer when processed by the strcpy function. Successful exploitation may cause memory corruption and could allow an attacker to affect the device’s confidentiality, integrity, or availability,” the company explained in a Friday advisory.

    “This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.”

    D-Link is also investigating a second vulnerability with public PoC exploit code affecting DIR-822A routers, a critical out-of-bounds write (CVE-2026-86510) in the L2TP control message parser reported by the same researcher.

    Threat actors with basic privileges may exploit CVE-2026-86510 to trigger arbitrary memory corruption by manipulating input data to cause an out-of-bounds write in attacks targeting devices configured to use L2TP or L2TPv6 WAN connectivity.

    While D-Link is still investigating the two flaws and working on security patches, it advised customers to ensure their DIR-822A routers are not exposed online, restrict remote management access, and limit administrative access to trusted systems and users via firewall or network-access controls.

    Although it has not flagged these vulnerabilities as exploited in attacks, attackers often target vulnerable D-Link devices, infect them with malware, and add them to large-scale botnets used for distributed denial-of-service (DDoS) attacks.

    The Cybersecurity and Infrastructure Security Agency (CISA) tracks 26 D-Link security flaws that have been or are still exploited in attacks, two of which ransomware gangs have also abused.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Bug DIR822A DLink Max routers severity warns ZeroDay
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft: September Windows updates break Always On VPN connections

    F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

    Ryuk ransomware member sentenced to 24 months in prison

    Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    Check Point warns of Management Server zero-day exploited in attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Perenco on offshore platform electrification quest to power Brazil’s shallow-water fields from shore

    September 23, 2026

    Federal immigration policy may be worsening Wisconsin’s caregiver shortage, leaders say

    September 23, 2026

    Trump-Xi Summit: What to Expect on AI, Trade, Critical Minerals

    September 23, 2026

    Video of protests in Greece isn’t recent

    September 23, 2026
    Latest Posts

    COLDCARD security audit phishing attack installs remote access tool

    August 5, 2026

    Reddit aims to make ‘karma’ less important for first-time posters with shift to AI moderation tools

    August 5, 2026

    Right turn on green: is the Telegraph changing its tune on the climate? | Daily Telegraph

    August 5, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Perenco on offshore platform electrification quest to power Brazil’s shallow-water fields from shore

    September 23, 2026

    Federal immigration policy may be worsening Wisconsin’s caregiver shortage, leaders say

    September 23, 2026

    Trump-Xi Summit: What to Expect on AI, Trade, Critical Minerals

    September 23, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.