D-Link DIR-822A Routers Face Unpatched Critical Flaws

Legacy D-Link routers have critical flaws with public exploit code and no patch, posing immediate risks to local networks.
Key points
- D-Link DIR-822A routers have two critical vulnerabilities with public exploit code and no available patch.
- Attackers on the local network can exploit these flaws without authentication to crash the device or execute code.
- Users should isolate these routers from the internet and restrict remote access until security patches are released.
Owners of D-Link DIR-822A routers face a serious security threat after the manufacturer disclosed two critical vulnerabilities that currently lack a fix. The issues allow attackers on the same local network to crash the device or potentially seize control without needing any login credentials.
BleepingComputer reported that D-Link has issued warnings about these flaws, which carry the maximum severity rating. Because public exploit code is already available, the risk of real-world attacks is significantly higher than usual for unpatched devices.
Critical flaws allow easy network attacks
The primary vulnerability, identified as CVE-2026-86296, exists in the router's DHCP server component. It stems from poor handling of data that causes a stack-based buffer overflow. An attacker can send specially crafted packets to trigger this error, leading to memory corruption that might result in remote code execution.
A second flaw, CVE-2026-86510, affects the L2TP control message parser. This out-of-bounds write error could also allow memory corruption if the router is configured to use specific WAN connectivity types. Both bugs require the attacker to be on the local network, but no authentication is needed to initiate the attack.
Public exploit code raises urgency
The security researcher who discovered these issues has published proof-of-concept exploit code. This means the technical steps to exploit the flaws are no longer a secret, lowering the barrier for malicious actors to weaponize the bugs. D-Link has not confirmed active exploitation yet, but the presence of public code makes rapid attacks more likely.
Users must take manual precautions
Since D-Link is still working on patches, users must take immediate manual steps to protect their networks. The company advises ensuring these routers are not exposed to the public internet and restricting remote management access. Limiting administrative access to trusted systems via firewall rules is also recommended to reduce the attack surface.
Historical data shows that vulnerable D-Link devices are frequent targets for botnets and distributed denial-of-service attacks. The US CISA agency tracks multiple D-Link flaws that have been exploited in the past, highlighting the ongoing risk associated with legacy hardware that lacks timely security updates.






