Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-86296: D-Link DIR-822A allows remote code execution
CVE-2026-86296 · published 20 days ago
Summary
The router's built‑in DHCP client contains a coding error that can be triggered over the network, letting an attacker run their own code on the device. This could let a bad actor take control of the router and intercept traffic. Install the latest firmware from D‑Link as soon as it is available or contact your vendor for a patch.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dir-822a | A_101 |
Original advisory text
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-b...
A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Severity
9.3
Critical
CVSS 3.1: 10.0 (MITRE)
Exploitation
EPSS 2%
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published7 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta