LiMP VPN
← All news

D-Link Won't Patch Critical Zero-Day in DIR-822A Routers

D-Link Won't Patch Critical Zero-Day in DIR-822A Routers

In short: On September 28, 2026, D-Link confirmed two critical zero-day vulnerabilities in its DIR-822A home Wi-Fi router. One of them, CVE-2026-86296, received the maximum CVSS score of 10.0 and lets an attacker take over the device without a password or any user interaction — a public proof-of-concept exploit is already circulating. The model is officially end-of-life, and D-Link has no plans to ship a patch. The only real defense is checking whether you have this router at home and restricting access to it or replacing it.

What happened

An independent researcher reported two vulnerabilities in the D-Link DIR-822A router (firmware version A_101). The first, CVE-2026-86296, is a stack-based buffer overflow caused by improper handling in the device's lightweight DHCP server component: an attacker on the same local network can send a specially crafted DHCP packet without any authentication and crash the DHCP daemon, or in the worst case achieve remote code execution. Its CVSS score is 10.0 out of 10 — the maximum on the scale — and a public proof-of-concept exploit has already been released.

The second flaw, CVE-2026-86510, is an out-of-bounds write in the L2TP tunnel-handling function (tunnel_set_params), scored 9.9 on CVSS v3.1 and 9.4 on CVSS v4.0. Both issues affect the same DIR-822A firmware version. If you haven't reviewed your own router's basic security settings yet, our step-by-step router security checklist is a good place to start.

Why there won't be a patch

D-Link has officially classified the DIR-822A as end-of-life. The company has done the same before with similarly critical flaws in other old models — for example, the DIR-878, where two CVSS 9.9 bugs have gone unpatched since the line reached end of support in 2021. For the DIR-822A, D-Link has published only risk-mitigation advice rather than a firmware update.

In practice, that means: if you or your relatives still have a DIR-822A at home, the vulnerability stays in the device permanently until it's replaced. Since a public exploit for CVE-2026-86296 already exists, the risk of mass automated scanning and attacks is not hypothetical — it's a practical, ongoing one.

What this means for your home network

A router is not just another gadget — it's the entry point for your entire home network, carrying traffic from banking apps, work email, smart cameras and speakers. Taking over a router lets an attacker redirect DNS to fake sites, intercept unencrypted traffic, or enroll the device into a botnet for further attacks. The real danger of the DHCP flaw is that it needs no administrator password — being on the same network is enough, including through a compromised IoT device or an open guest network.

If you already run a VPN client on your router to protect your whole home network, it helps to know the boundary: encrypting traffic through LiMP VPN protects data in transit, but it doesn't close a vulnerability in the router's own firmware — these are different layers of protection, and we break down how they work together in our guide on protecting a home network with a VPN.

Do I need to do anything right now?

Yes, if you or your relatives use specifically the D-Link DIR-822A model. Check the model on the label underneath the device or in the admin web panel (usually at 192.168.0.1 or 192.168.1.1).

  • Disable remote management of the router from the internet — this setting is usually found under "Remote Access" or "Remote Management" in the web panel.
  • Restrict access to the web interface to devices on your local network only, if the firmware supports it.
  • Isolate IoT devices (cameras, speakers, smart bulbs) on a separate guest network — an access point compromised through the DHCP flaw won't have a direct path to the computers and phones on your main network.
  • Plan to replace the router — for a device the vendor officially won't patch, this is a matter of "when," not "if."
  • These steps don't replace a strong admin and Wi-Fi password, but skipping that basic step raises the risk further — change factory defaults if you haven't already.

Sources