Tendvane

← All articles

NetworkSeptember 22, 2026

A router flaw scored 10 out of 10. There is no patch.

D-Link's advisory for the DIR-822A carries a severity score of 10.0. There is no higher number.

The flaw, CVE-2026-86296, sits in the router's DHCP service, the part that hands out addresses to everything that joins your network. One sloppy line, a strcpy call in udhcpcd/serverpacket.c, lets an oversized request run off the end of a buffer and drop an attacker's instructions where the router's own should be. No password required. Anything already on the network can send it, which in a normal house means a guest's phone, a smart plug, a cheap camera or a laptop that picked something up. A second bug, CVE-2026-86510, corrupts memory through the router's L2TP parser and scores 9.9. Working proof-of-concept code for both is public.

D-Link published advisory SAP10516 on 18 September and updated it on 21 September, and the update contains no fix. The company is still working out which hardware revisions and which regions are affected, and whether this model is old enough that no firmware is coming at all. The version named in the reports is A_101 on the non-US DIR-822A. Until something ships, D-Link's own advice is the sensible kind: turn off remote management so the admin page cannot be reached from the internet, and keep the router's settings page off any network you would not trust.

Do this regardless of what brand is on your box. Log into the router today, note the firmware version, check whether remote management is switched on, and see whether the manufacturer has released anything at all this year. A router that stopped getting updates three years ago is usually the weakest thing in the house. Tendvane's network scan lists every device currently connected to yours, which is a quick way to notice hardware you had forgotten was there.

Sources

Download Tendvane