Stack-Based Buffer Overflow in D-Link Router Firmware
CVE-2026-86296

10CRITICAL

Key Information:

Vendor

D-link

Status
Vendor
CVE Published:
7 September 2026

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2026-86296?

A vulnerability exists in the D-Link DIR-822A A_101 router related to the strcpy function within the udhcpcd/serverpacket.c file. This weakness can lead to a stack-based buffer overflow, allowing attackers to exploit the vulnerability remotely. The potential risks include unauthorized access and manipulation of data within the affected device. The exploit has been publicly disclosed, raising concerns for users of this router model. It is essential for users to apply necessary updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

DIR-822A A_101

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.

1 week ago

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • πŸ“°

    First article discovered by BleepingComputer

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

tian (VulDB User)
.