CVE-2026-86510
CRITICALCVSS 9.9Description
A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Timeline
Published:September 8th, 2026 2:17 AM
Last modified:September 8th, 2026 2:17 AM
CVSS Scoring
CVSS v3: 9.9 (CRITICAL)
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2: 9.0
References & Reports
Advisories, patches, and third-party reports
Source: NIST NVD · Data may lag official sources by up to one minute