A stack-based buffer overflow vulnerability has been identified in the D-Link DIR-822A router (firmware version A_101). The vulnerability resides in the strcpy function within the udhcpcd/serverpacket.c file of the udhcpcd component, related to TR-111 Option 125 parsing. An attacker can exploit this vulnerability remotely without requiring physical access to the device. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability has been assigned CVE-2026-86296 and is tracked on NVD and VulDB. D-Link home/SMB routers are the affected products, posing a risk to network infrastructure. Users are advised to monitor for patches from D-Link and apply mitigations promptly.