CVE-2026-86510: D-Link DIR-822A L2TP Control Message tunnel_set_params out-of-bounds write
A vulnerability has been found in D-Link DIR-822A A101. Affected is the function tunnelsetparams of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments are affected?
The affected product identified is D-Link DIR-822A running version A_101. The vulnerable component is the L2TP Control Message Parser.
What level of access does an attacker need?
The attack can be launched remotely and requires low privileges. No user interaction is required.
How serious is successful exploitation?
Successful exploitation can cause an out-of-bounds write and is rated critical with a 9.9 severity score. The supplied vector indicates potential high impact to confidentiality, integrity, and availability, including impacts beyond the vulnerable security authority.
Is exploit activity a practical concern?
Yes. A public exploit has been disclosed and may be used.