
D-Link has warned customers of a maximum-severity vulnerability in its DIR-822A dual-band Wi-Fi router. Tracked as CVE-2026-86296 and scored CVSS 10.0, the flaw is a stack-based buffer overflow in the router’s DHCP server component. Because the DIR-822A is a legacy product, D-Link has confirmed it will not release a patch — the device has reached end-of-life.
The attack requires no authentication and no action from any user. Anyone on the same local network can send specially crafted DHCP packets to the router, overflow the stack buffer in the strcpy processing path, and potentially crash the DHCP daemon or achieve remote code execution on the device. A proof-of-concept exploit has already been published by the researcher who discovered the bug, lowering the bar for exploitation considerably.
How to check if you’re affected
Affected devices are D-Link DIR-822A dual-band Wi-Fi routers. Check the label on the bottom of your router or log into its admin panel (usually at 192.168.0.1) to confirm the model. If you have a DIR-822A, D-Link’s advice is to retire and replace it — no firmware fix is planned for CVE-2026-86296. As a temporary measure, restrict physical and logical access to your local network; the vulnerability requires LAN-side access, so an isolated or guest-only segment won’t be reachable by external attackers, but any device already on your Wi-Fi can exploit it.
