Разработчики D-Link предупредили о неисправленном 0-day-баге в роутерах DIR-822A
PoC publicDIR-822AOur summary
D-Link has disclosed two unpatched vulnerabilities in its end-of-life DIR-822A dual-band routers: CVE-2026-86296 and CVE-2026-86510. Public PoCs are available for both flaws; CVE-2026-86296 can let an unauthenticated attacker on the local network disrupt DHCP or potentially execute code, while CVE-2026-86510 affects devices using L2TP or L2TPv6 for WAN and involves an out-of-bounds write. Until fixes arrive, owners should prevent direct internet exposure, restrict remote administration, and limit management access to trusted users and systems.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.