BlackTree Security · Infrastructure · Automation · AI

D-Link Is Still Investigating Two Critical Router Flaws With Public Exploit Code

D-Link is investigating two critical vulnerabilities in the DIR-822A router while public proof-of-concept code is already available. Its advisory did not list fixed firmware at publication time, leaving owners with an exposure decision rather than a routine patching task.

CVE-2026-86296 is an unauthenticated stack-based buffer overflow rated 10.0. D-Link says a remote attacker can trigger it through a crafted request. CVE-2026-86510 is an out-of-bounds write rated 9.9 and requires a low-privilege account.

Public code changes the defender’s timetable

A public proof of concept is not evidence of active exploitation. It does, however, reduce the work needed to study and reproduce a flaw. Scanners, researchers and attackers can all begin testing before a vendor has completed its investigation.

D-Link identifies DIR-822A firmware A_101 in the advisory. Model names and regional hardware revisions matter, so teams should not assume that a visually similar router has the same firmware or vulnerability status.

What owners can do while there is no listed fix

  • Confirm the exact model and revision. Record the hardware revision and installed firmware rather than relying on the product family name.
  • Remove internet exposure. Disable remote administration and block access to management services from untrusted networks.
  • Limit local management. Restrict the interface to named administration devices or a dedicated management segment.
  • Review accounts. Because CVE-2026-86510 needs only low privileges, remove unused users and rotate credentials that may have been shared.
  • Monitor the advisory. Do not obtain unofficial firmware from third-party sites while waiting for D-Link’s investigation.
  • Consider replacement. If a vulnerable router protects sensitive or business-critical systems, isolation or replacement may be safer than waiting with the interface exposed.

There is no basis yet to claim that either vulnerability is being exploited in the wild. The defensible statement is narrower: public code exists, the severity is critical and D-Link had not announced a corrected release when it published the advisory.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *