

Affected Environment
D-Link DIR-822A routers running firmware version A_101, widely deployed in home and small business networks.
Threat Overview
A stack-based buffer overflow and an L2TP out-of-bounds write enable code execution and memory corruption.
Exposure Timeline
Publicly disclosed 22 September 2026 with a maximum CVSS score of 10; no vendor patch yet confirmed.
Attack Surface
Unauthenticated LAN DHCP traffic and L2TP or L2TPv6 WAN tunnel setup traffic on affected devices.
Technical Root Cause
Unsafe strcpy use in DHCP option 125 parsing and an oversized L2TP Host Name AVP.
Exploitation Pathway
Attacker sends a crafted DHCP or L2TP control packet to trigger memory corruption and code execution.
Operational Impact
Arbitrary code execution, memory corruption, denial of service, or full compromise of the router.
Strategic Impact
Critical for all entities given widespread router deployment and lack of a confirmed vendor patch.
Required Mitigation
Restrict internet exposure, disable remote management, and monitor D-Link's regional support portal for updates.
Incident Response Guidance
Inventory all DIR-822A devices on firmware A_101 and restrict administrative interface access immediately.
References
cybersecuritynews.com, tzh00203.notion.site advisories.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




