Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-86510: D-Link DIR-822A router can be remotely corrupted
CVE-2026-86510 · published 19 days ago
Summary
The router’s L2TP tunnel handling can be tricked into writing data outside its memory space. An attacker on the network could use this to take control of the device. Install the latest D‑Link firmware or disable L2TP if it is not needed.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dir-822a | A_101 |
Original advisory text
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The...
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity
8.6
High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-787Out-of-bounds Write
CWE-119Buffer Overflow
Timeline
Published8 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Track software like this
Free during beta