D-Link Systems has identified a critical security vulnerability in its DIR-822A router, tracked as CVE-2026-86296 This article explores affects udhcpcd. . It could allow remote attackers to compromise devices without authentication or user interaction.

The issue affects the udhcpcd component in the DIR-822A firmware version A_101, specifically in the udhcpcd/serverpacket.c source file, where the strcpy function is used to copy attacker-controlled data into a fixed-size stack buffer. If the crafted input exceeds available buffer space, it can overwrite adjacent memory, leading to device crashes, service disruptions, or even allow an attacker to run unauthorized code on the router. D-Link is investigating the vulnerability, but has not yet confirmed affected hardware revisions, regional product scope, or firmware remediation status.

This issue is classified under Stack-Based Buffer Overflow and Improper Restriction of Operations within the Bounds of a Memory Buffer. The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R. Organizations using the affected router should treat the issue as a high-priority exposure-management concern, even while D-Link continues its validation efforts. D-Link advises DIR-822A owners to verify their exact model, hardware revision, and installed firmware version before taking any action.

Users should avoid exposing their router administration interfaces to the internet, turn off remote management when it's not necessary, and restrict administrative access to trusted systems.