Junglewise Threat Intelligence

CVE-2026-6014: D-Link DIR-513 buffer overflow in formAdvanceSetup

CVE-2026-6014 · Severity: high · CVSS 8.8 · Published 2026-04-10

Technologies: Dlink Dir-513 Firmware, Dlink Dir-513. Vendors: Dlink, D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DIR-513 router, a device used to provide wireless networking for homes or small offices. An attacker can exploit this flaw to cause a system crash or potentially take control of the device by sending a specially crafted web request. This product is no longer supported by the manufacturer, meaning no official security updates will be released to fix this issue.

Technical details

A classic buffer overflow vulnerability exists in the D-Link DIR-513 firmware version 1.10. The flaw is located within the 'formAdvanceSetup' function of the '/goform/formAdvanceSetup' endpoint, which serves as a POST request handler. By manipulating the 'webpage' argument, a remote attacker with low privileges can trigger a memory corruption. This can lead to arbitrary code execution or a complete system crash (DoS). Public exploit code is reportedly available. As the device is end-of-life (EOL), no patch is expected from the vendor.

Affected products

  • D-Link DIR-513 1.10

Timeline

  • 2026-04-10: disclosed: Initial vulnerability disclosure
  • 2026-04-10: advisory: NVD publication date

References

Related threats