Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-86509: D-Link DIR-895L may let local attacker take control

CVE-2026-86509 · published 1 month ago
Summary

The router’s built‑in service that hands out IP addresses can be confused by a specially crafted message, causing it to crash or allow a nearby user to gain unauthorized access. This can only be done by someone connected to the same local network. Apply the latest firmware from D‑Link as soon as possible, or temporarily disable the automatic IP address service until the update is installed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dir-895l A1_102b07
Original advisory text
D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.6 High
Exploitation
<1% chance of attack within 30 days
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published8 Sep 2026
Updated7 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-86509 · MITRE
Track software like this
Free during beta