---
id: CVE-2026-86510
title: A vulnerability has been found in D-Link DIR-822A A_101
summary: >-
  A vulnerability has been found in D-Link DIR-822A A_101. Affected is the
  function tunnel_set_params of the component L2TP Control Message Parser. Such
  manipulation leads to out-of-bounds write. The attack can be launched
  remotely. The ex…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-119
  - CWE-787
vendor: D-Link
product: DIR-822A
affected:
  - DIR-822A A_101
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T17:18:39.887'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86510'
references:
  - url: >-
      https://tzh00203.notion.site/D-Link-DIR-822A-L2TP-Host-Name-AVP-Out-of-Bounds-Write-33cb5c52018a80a7af5fdc1af3d5aa73
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86510'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/906300'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399663'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399663/cti'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00511
epssPercentile: 0.41123
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-08T16:04:12.456981Z'
ingestedAt: '2026-09-08T17:06:31.935Z'
---

## Overview

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
