Executive brief
A security vulnerability exists in the D-Link DIR-513 router, a device used to provide wireless networking for homes or small offices. An attacker could exploit this flaw to take control of the device or cause it to crash, potentially leading to a complete loss of internet connectivity and unauthorized access to the local network. Because this product is no longer supported by the manufacturer, no official security updates will be released, and users are advised to replace the device.
Technical details
A stack-based buffer overflow vulnerability exists in the D-Link DIR-513 router (firmware version 1.10) within the POST Request Handler component. Specifically, the 'formSetRoute' function in the '/goform/formSetRoute' file fails to properly validate the length of the 'curTime' argument. A remote attacker with low-level privileges can exploit this by sending a specially crafted POST request to overwrite memory, potentially leading to remote code execution (RCE) or a denial of service (DoS). This product is end-of-life (EOL), and public exploit code is reportedly available.
Affected products
- D-Link DIR-513 1.10
Timeline
- 2026-04-10: advisory: Initial disclosure by VulDB and NVD