Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.6

CVE-2026-86510: D-Link DIR-822A router can be remotely corrupted

CVE-2026-86510 · published 19 days ago
Summary

The router’s L2TP tunnel handling can be tricked into writing data outside its memory space. An attacker on the network could use this to take control of the device. Install the latest D‑Link firmware or disable L2TP if it is not needed.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dir-822a A_101
Original advisory text
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The...
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Severity
8.6 High
CVSS 3.1: 9.9 (MITRE)
Exploitation
EPSS <1%
Type
CWE-787Out-of-bounds Write
CWE-119Buffer Overflow
Timeline
Published8 Sep 2026
Updated27 Sep 2026
First seen8 Sep 2026
Sources
CVE-2026-86510 · MITRE
Track software like this
Free during beta