Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-86509: D-Link DIR-895L may let local attacker take control
CVE-2026-86509 · published 1 month ago
Summary
The router’s built‑in service that hands out IP addresses can be confused by a specially crafted message, causing it to crash or allow a nearby user to gain unauthorized access. This can only be done by someone connected to the same local network. Apply the latest firmware from D‑Link as soon as possible, or temporarily disable the automatic IP address service until the update is installed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dir-895l | A1_102b07 |
Original advisory text
D-Link DIR-895L udhcpcd serverpacket.c sendACK stack-based overflow
A flaw has been found in D-Link DIR-895L A1_102b07. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack can only be done within the local network. The exploit has been published and may be used.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.6
High
Type
CWE-121Stack-based Buffer Overflow
CWE-119Buffer Overflow
Timeline
Published8 Sep 2026
Updated7 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta