Junglewise Threat Intelligence

CVE-2026-6012: D-Link DIR-513 buffer overflow in formSetPassword

CVE-2026-6012 · Severity: high · CVSS 8.8 · Published 2026-04-10

Technologies: Dlink Dir-513 Firmware, Dlink Dir-513. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability exists in the D-Link DIR-513 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to cause a system crash or potentially take full control of the device by sending a specially crafted web request. Because this product is no longer supported by the manufacturer, no official security updates will be released, leaving affected devices permanently vulnerable.

Technical details

A stack-based buffer overflow vulnerability exists in the D-Link DIR-513 firmware version 1.10. The flaw is located within the 'formSetPassword' function in the '/goform/formSetPassword' file, which serves as a POST request handler. By manipulating the 'curTime' argument in a remote POST request, an authenticated attacker can overflow a memory buffer. This can lead to arbitrary code execution or a device crash. As the product is end-of-life (EOL), no patch is available, and public exploit code has been disclosed.

Affected products

  • D-Link DIR-513 1.10

Timeline

  • 2026-04-10: disclosed: Vulnerability disclosed and CVE assigned
  • 2026-04-10: advisory: Initial advisory published by VulDB

References

Related threats