Stack-Based Buffer Overflow in D-Link Router Firmware
CVE-2026-86296
Key Information:
Badges
What is CVE-2026-86296?
A vulnerability exists in the D-Link DIR-822A A_101 router related to the strcpy function within the udhcpcd/serverpacket.c file. This weakness can lead to a stack-based buffer overflow, allowing attackers to exploit the vulnerability remotely. The potential risks include unauthorized access and manipulation of data within the affected device. The exploit has been publicly disclosed, raising concerns for users of this router model. It is essential for users to apply necessary updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
DIR-822A A_101
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
D-Link warns of max severity zero-day bug in DIR-822A routers
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
1 week ago
References
CVSS V4
Timeline
- π°
First article discovered by BleepingComputer
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved