Executive brief
A security vulnerability exists in the D-Link DIR-513 router, a device used to provide wireless internet connectivity. An attacker can exploit this flaw to cause a system crash or potentially take full control of the device by sending a specially crafted web request. Because this product is no longer supported by the manufacturer, no official security updates will be released, leaving affected devices permanently vulnerable.
Technical details
A stack-based buffer overflow vulnerability exists in the D-Link DIR-513 firmware version 1.10. The flaw is located within the 'formSetPassword' function in the '/goform/formSetPassword' file, which serves as a POST request handler. By manipulating the 'curTime' argument in a remote POST request, an authenticated attacker can overflow a memory buffer. This can lead to arbitrary code execution or a device crash. As the product is end-of-life (EOL), no patch is available, and public exploit code has been disclosed.
Affected products
- D-Link DIR-513 1.10
Timeline
- 2026-04-10: disclosed: Vulnerability disclosed and CVE assigned
- 2026-04-10: advisory: Initial advisory published by VulDB