{
  "id": 12675721,
  "title": "Two Critical Bugs, One Router: What the D-Link DIR-822A Disclosures Mean for Home Networks",
  "url": "https://urgent.news/2026/10/07/two-critical-bugs-one-router-what-the-d-link-dir-822a-disclosures",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-10-07T17:40:37.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/bianliang/two-critical-bugs-one-router-what-the-d-link-dir-822a-disclosures-mean-for-home-networks-4mji"
  },
  "original_language": "en",
  "account": "Two critical security flaws were recently discovered in the D-Link DIR-822A router, a common home networking device. The vulnerabilities, CVE-2026-86296 and CVE-2026-86510, are both memory safety issues that can be exploited to crash the device or potentially execute arbitrary code.\n\nThe first flaw, CVE-2026-86510, is a stack buffer overflow in the L2TP control message parser. This function, tunnel_set_params, copies attacker-supplied data into a fixed-size structure without checking the length. If the attacker crafts a message longer than the buffer can handle, it overwrites adjacent memory locations. The second flaw, CVE-2026-86296, is a stack overflow in the DHCP server's TR-111 option 125 parsing path. Here, binary subfields are treated as null-terminated strings and copied into 256-byte stack buffers using strcpy. If the attacker creates a specially crafted packet, this can also cause a buffer overflow.\n\nBoth bugs require the attacker to be on the same local network as the vulnerable router. They do not appear to be exploitable from the internet without first gaining access to the network. Exploitation depends on the specific router configuration and memory layout, but either flaw could lead to the attacker taking control of the device and using it to compromise other devices on the network.\n\nD-Link has been notified of the vulnerabilities, but no official patch has been released yet. Users of the affected DIR-822A router with firmware A_101 are advised to take protective measures until a fix is available. These include isolating the router on a trusted network segment, disabling remote management features accessible from the internet, and segmenting any guest Wi-Fi networks from the main administration interface. Regularly checking D-Link's security advisories and being prepared to replace the device if no patch is issued are also recommended steps to mitigate the risk.",
  "summary": "Two Critical Bugs, One Router: What the D-Link DIR-822A Disclosures Mean for Home Networks Vulnerability overview Two memory-safety defects were disclosed in the D-Link DIR-822A router on the same day, and they are easy to confuse. CVE-2026-86296 is a stack buffer overflow in the DHCP server, rated 10.0. CVE-2026-86510 is an out-of-bounds write in the L2TP control message parser, rated 9.9. Both…",
  "key_points": [
    "Two critical security flaws discovered in D-Link DIR-822A router",
    "CVE-2026-86296 and CVE-2026-86510 are memory safety issues",
    "Vulnerabilities could crash device or execute arbitrary code"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}