D-Link Confirmed Critical Flaws in Legacy Routers

The manufacturer identified two vulnerabilities in DIR-822A routers, yet no security patches are currently available.

Updated on Sept. 22, 2026 in Cybersecurity

Isometric editorial illustration of a matte dark grey router chassis with internal copper wiring lattice, representing network hardware security risks.
D-Link has confirmed two critical security vulnerabilities in its legacy DIR-822A routers, confirming that no firmware patches are currently available to fix the flaws. AI Illustration. Upload story photo >

Live Poll

Do you feel responsible for manually updating home network security to prevent remote cyber attacks?

D-Link disclosed two security flaws in its legacy DIR-822A dual-band Wi-Fi routers that lack available patches. The most severe issue, identified as CVE-2026-86296, enables unauthenticated remote code execution.

Why it matters

The vulnerabilities present significant security risks to users of this hardware, as the flaws require no user interaction to exploit. D-Link has not yet provided a timeline for the release of firmware updates to address these vulnerabilities.

CVE-2026-86296 represents a maximum-severity stack-based buffer overflow, while CVE-2026-86510 is a critical out-of-bounds write vulnerability in the L2TP control message parser.

The players

D-Link

A networking equipment manufacturer specializing in routers, switches, and home automation hardware.

CISA

The Cybersecurity and Infrastructure Security Agency, which maintains databases of known vulnerabilities and hardware security risks.

The details

The stack-based buffer overflow occurs when the DHCP server component processes crafted packets that exceed the available buffer allocated to the strcpy function, a standard C library routine used to copy strings. By sending these specific data packets, an attacker can bypass the device's security controls without authentication or user interaction. A secondary flaw in the L2TP control message parser—a network protocol used to support virtual private networks—further exposes the router to exploitation.

Timeline

  1. September 18, 2026: D-Link issued the official security advisory regarding the vulnerabilities.

The Tech Race

This disclosure adds to the existing total of 26 D-Link security issues being monitored by CISA. The ongoing effort highlights the persistent challenge in securing legacy network infrastructure against modern exploitation methods.

Users of the DIR-822A router face heightened security risks as no patches are available to mitigate these vulnerabilities. Owners should monitor the D-Link support portal for upcoming firmware updates or consider network isolation measures until a remediation path is provided.

The takeaway

These unpatched vulnerabilities emphasize the critical need for users to audit legacy networking equipment for active security disclosures. Watch for the eventual release of manufacturer firmware updates as the primary path to resolving the underlying stack-based buffer overflow issues.

Further reading

For broader trends in network device hardening, visit our Cybersecurity section.

Live Poll

Do you feel responsible for manually updating home network security to prevent remote cyber attacks?

D-Link Confirmed Critical Flaws in Legacy Routers