Junglewise Threat Intelligence

CVE-2026-86296: D-Link DIR-822A stack-based buffer overflow in udhcpcd

CVE-2026-86296 · Severity: critical · CVSS 10 · Published 2026-09-07

Vendors: D-Link.

Executive brief

The D-Link DIR-822A wireless router contains a stack-based buffer overflow vulnerability in its DHCP server component (udhcpcd). An attacker on the network can trigger this vulnerability remotely to crash the device or execute arbitrary code, potentially gaining full control of the router and accessing connected devices or networks.

Technical details

A stack-based buffer overflow exists in the udhcpcd component of D-Link DIR-822A firmware version A_101, specifically in the strcpy function within udhcpcd/serverpacket.c. The vulnerability is triggered during processing of DHCP option 125 (TR-111), where insufficient bounds checking allows an attacker to write beyond allocated buffer boundaries on the stack. The vulnerability is remotely exploitable without authentication or user interaction; an attacker can send a specially crafted DHCP request to trigger the overflow. Successful exploitation may lead to denial of service or remote code execution with router-level privileges. Fix status and patches have not been identified.

Affected products

  • D-Link DIR-822A A_101

Timeline

  • 2026-09-07: disclosed: Vulnerability publicly disclosed

References

Related threats