PoC public DIR-822A zero-day D-Link rce
D-Link warns of max severity zero-day bug in DIR-822A routers
CVE Tools coverage
D-Link has disclosed two unpatched vulnerabilities with public PoC code affecting legacy DIR-822A dual-band Wi-Fi routers: CVE-2026-86296 and CVE-2026-86510. CVE-2026-86296 is an unauthenticated DHCP server stack buffer overflow that could let an attacker on the local network crash the service or execute code, while CVE-2026-86510 can cause memory corruption on devices using L2TP or L2TPv6 WAN connectivity. D-Link is investigating and developing fixes; customers should keep these routers off the internet, limit remote management, and restrict administrative access to trusted systems.