D-Link's DIR-822A firmware A_101 has two critical flaws, scored 9.9 and 10.0, with public proof-of-concept code and no fixed release yet. Until D-Link ships a build, owners are left isolating the router from untrusted networks or planning its replacement.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
CERT Polska dated successful attacks to at least September 2 and published its warning on September 5, so operators who deferred the RouterOS update have three days of configuration changes to read as well as a patch to install.
Perspective Coverage
8 publishers
- Builder
- Builder 19%
- Operator
- Operator 73%
- Investor
- Investor 8%
Reality
- Evidence78
- Adoption45
- Hype gap+18
- Incentives30
- Confidence72
VulDB scored CVE-2026-86296 at 10.0 because a crafted DHCP request reaches the DIR-822A's udhcpcd with no credentials and no user interaction, while D-Link is still working out which hardware revisions are affected.
Perspective Coverage
3 publishers
- Builder
- Builder 17%
- Operator
- Operator 75%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+15
- Incentives40
- Confidence66
CERT Polska's breakdown of the September RouterOS compromises names two bugs, CVE-2026-67279 and CVE-2026-86060, and the forum logs that match the chain start on September 2, a day before MikroTik shipped fixes.
Reality
- Evidence74
- Adoption52
- Hype gap−8
- Incentives35
- Confidence70