"A specially crafted request may cause data to exceed the available stack buffer when processed by the strcpy function," D‑Link wrote in a Friday advisory.
The DHCP stack overflow in udhcpcd/serverpacket.c
D‑Link has disclosed a maximum-severity, unauthenticated zero-day affecting DIR‑822A routers that stems from a stack-based buffer overflow in the device's DHCP server component. The company traces the flaw to the strcpy call in udhcpcd/serverpacket.c. According to the advisory, attackers on the same local network — without valid credentials and without any user interaction — can send crafted DHCP packets that trigger the overflow. Successful exploitation may crash the device's DHCP daemon or achieve remote code execution and thereby affect confidentiality, integrity, or availability.
Public proof-of-concept increases weaponization risk
D‑Link warned that the researcher who reported the bug has published a proof‑of‑concept exploit. The vendor said the exploit has been publicly disclosed and "may be utilized," a phrase that underlines the practical risk: once a working PoC is available, the window for weaponization in the wild narrows and opportunistic attackers can test and adapt exploits rapidly.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleCVE‑2026‑86510: out‑of‑bounds write in L2TP control message parser
In addition to the DHCP stack overflow, D‑Link is investigating a second vulnerability affecting DIR‑822A routers: a critical out‑of‑bounds write tracked as CVE‑2026‑86510 in the L2TP control message parser. Reported by the same researcher, the flaw can be abused by threat actors with basic privileges to trigger arbitrary memory corruption. D‑Link's advisory notes the attack targets devices configured to use L2TP or L2TPv6 for WAN connectivity and depends on manipulating input data to cause the out‑of‑bounds write.
D‑Link's guidance and patch status
D‑Link said it is investigating both flaws and is "working on security patches." While patches are under development, the company advised DIR‑822A customers to reduce exposure: ensure routers are not reachable from the public internet, restrict remote management access, and limit administrative access to trusted systems and users via firewall or network‑access controls. The vendor also noted that, so far, it has not flagged these specific vulnerabilities as exploited in active attacks.
What this means for technologists, CISA, and end users
- Technologists and security teams: The public PoC and the unauthenticated nature of the DHCP flaw mean defenders should prioritize network segmentation and temporary hardening measures for DIR‑822A devices — particularly removing any internet exposure and disabling remote management until vendor patches are available.
- CISA and regulators: The advisory arrives against a backdrop the vendor acknowledged: the Cybersecurity and Infrastructure Security Agency tracks 26 D‑Link security flaws that have been or remain exploited in attacks, including two abused by ransomware gangs. That record is the context for elevated scrutiny and an urgency to receive timely patches and telemetry from affected networks.
- End users and home/SMB operators: Owners of DIR‑822A routers should follow D‑Link's immediate mitigations — ensure devices are not exposed online, restrict remote management, and apply network‑level controls to administrative interfaces — while awaiting vendor updates.
D‑Link's disclosure combines a technical diagnosis with pragmatic steps: the strcpy call in udhcpcd creates a classic buffer‑overflow pathway, and the availability of a public PoC accelerates the risk timeline. The company is investigating a second, L2TP‑related bug at the same time. Neither flaw has yet been flagged by D‑Link as seen in exploitation, but the vendor warned of the broader pattern of attackers targeting vulnerable D‑Link devices and of the large‑scale botnets that have historically leveraged such exposures for distributed denial‑of‑service activity. For operators of DIR‑822A equipment, that pattern and the public proof‑of‑concept together argue for swift hardening and close tracking of the vendor's forthcoming patches.
Original report: https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/




