Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-86296: D-Link DIR-822A allows remote code execution

CVE-2026-86296 · published 20 days ago
Summary

The router's built‑in DHCP client contains a coding error that can be triggered over the network, letting an attacker run their own code on the device. This could let a bad actor take control of the router and intercept traffic. Install the latest firmware from D‑Link as soon as it is available or contact your vendor for a patch.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dir-822a A_101
Original advisory text
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-b...
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Severity
9.3 Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS 2%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published7 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-86296 · MITRE
Track software like this
Free during beta