# D-Link investigates unpatched DIR-822A router flaws with public exploit code

_Published Tuesday, September 22, 2026 at 6:25 PM EDT · Security, Infrastructure · Latest · Tier 2 — Notable_

![D-Link investigates unpatched DIR-822A router flaws with public exploit code — Primary](https://www.bleepstatic.com/content/hl-images/2026/09/22/D-Link.jpg)

D-Link is investigating two DIR-822A router vulnerabilities for which proof-of-concept exploit code is public, while patches remain under development. One unauthenticated flaw in the DHCP server lets an attacker on the same local network send crafted packets that may crash the service or execute code. A second flaw can corrupt memory on routers using L2TP or L2TPv6 connections.

D-Link advises customers to prevent Internet exposure, restrict remote management and limit administration to trusted systems. The company has not reported either vulnerability being exploited in attacks.

## Sources

- [BleepingComputer](https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/)

---
Canonical: https://techandbusiness.org/newswire/iDIE4y8pJ0l95hvTnOjCLZ
Published: 2026-09-22T22:25:11.112Z
Story chronology: 2026-09-22T12:48:06.000Z
Retrieved: 2026-09-23T00:37:55.966Z
Publisher: Tech & Business (techandbusiness.org)
