important · Firmware
A LAN DHCP packet can overwrite the stack in D-Link DIR-822A firmware; code execution remains unproven.
Affects
D-Link DIR-822A, a dual-band Wi-Fi router running embedded firmware.
An unauthenticated DHCP packet from the LAN can corrupt the stack of the D-Link DIR-822A DHCP daemon. An overlong TR-111 Option 125 suboption reaches an unbounded strcpy into a bounded stack buffer in udhcpcd.
Detail and 6 sources
The held evidence does not demonstrate controlled instruction flow, command execution or the daemon's privilege context.
Sources
ResearchET EXPLOIT D-Link udhcpd option 125, Suboption 1-3 Buffer Overflow Attempt (CVE-2026-86296)ResearchD-Link DIR-822A: a 10.0 flaw, public exploit, and no fix on record | P.K. SharmaResearchAktuality ~ SK-CERTCode / PoCCVE-2026-86296 - GitHub Advisory DatabaseVendorD-Link Technical SupportVendorD-Link warns of max severity zero-day bug in DIR-822A routers