D-Link DIR-822A Maximum Severity Zero-Day Vulnerability
CVSS 10.0 vulnerability in D-Link DIR-822A legacy routers with public PoC and no patch. Device is end-of-life; D-Link recommends replacement.
- Vendor
- D-Link
- Product
- DIR-822A
- CVSS
- 10.0
- EPSS (exploit probability)
- 1.3%
- Status
- unpatched
- Published
CVE-2026-86296 affects the D-Link DIR-822A dual-band Wi-Fi router. D-Link has disclosed the flaw directly to customers and confirmed that no patch will be issued: the DIR-822A is past end of life.
Severity: CVSS 10.0 (Critical) per NVD.
Exploitation status: Public proof-of-concept exploit code is in circulation as of September 2026. No patch is available or planned. D-Link recommends replacing the device.
Recommended action: Treat this as a hardware replacement priority. If immediate replacement is not possible, do not expose the router directly to the internet. Place it behind a firewall and restrict external access until a replacement is in place.
For full coverage see D-Link Warns CVSS 10.0 DIR-822A Flaw Has No Fix.
