Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

Assessing CVE-2026-86510: Severity, Reachability and the Limits of the Public Record

Assessing CVE-2026-86510: Severity, Reachability and the Limits of the Public Record Vulnerability overview CVE-2026-86510 is an out-of-bounds write in the L2TP control message parser of the D-Link DIR-822A

Assessing CVE-2026-86510: Severity, Reachability and the Limits of the Public Record

Vulnerability overview

CVE-2026-86510 is an out-of-bounds write in the L2TP control message parser of the D-Link DIR-822A
router, scored 9.9. It was disclosed together with CVE-2026-86296, a 10.0 stack buffer overflow in
the same firmware's DHCP server. Both affect firmware A_101 and both have public proof-of-concept
code. Neither has confirmed in-the-wild exploitation.

Mechanism and exploitation conditions

The write happens in tunnel_set_params while the device processes an L2TP control message. The
parser copies fields from the message into a fixed structure without validating their length, so a
crafted message overruns the destination.
Two conditions shape the real-world risk. First, the attacker must be able to deliver L2TP control
traffic to the daemon, which implies local network access or an equivalent position. Second, the
exploit must survive the specific build's memory layout and mitigations. The public record
establishes the first condition and the existence of exploit code; it does not establish how
reliable that code is against every A_101 device.

Impact

At minimum, the bug allows an attacker with network access to corrupt memory in a privileged
daemon, which is enough to cause crashes and service disruption. At worst, it allows code execution
on a device that sits between the network and the internet. The gap between those two outcomes is
where most of the uncertainty in this disclosure lives, and it is worth stating plainly rather than
assuming the worst case is guaranteed.

Affected products and scope

D-Link DIR-822A running firmware A_101 is the confirmed affected configuration. The vendor has said
it is reviewing the affected product scope and remediation options, which means the scope statement
is provisional. No other model has been confirmed affected, and none has been confirmed unaffected.

Exposure context

ZoomEye returned 624 assets for the model title query title="DIR-822" and 6,697,454 assets for the broader vendor fingerprint app="D-Link". The vendor-wide number says nothing about which firmware is installed, so the model-specific count is the figure worth quoting. Even that number only proves that DIR-822 family devices are reachable from the internet or a scanned network; it does not prove that any of them are exploitable.

Remediation and mitigations

There is no patched firmware yet, so mitigation is about exposure reduction:

  • Keep the device off untrusted network segments.
  • Disable remote management from the WAN side.
  • Isolate guest networks from the administration interface.
  • Monitor D-Link's security advisories for a fixed release.
  • Budget for replacement if the model reaches end of support unpatched.

References

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.