CVE-2026-4555
8.8D-Link · DIR-513
A stack-based buffer overflow in the D-Link DIR-513 boa web server component allows remote authenticated attackers to execute arbitrary code via the curTime parameter in formEasySetTimezone.
Executive summary
A critical stack-based buffer overflow vulnerability in the D-Link DIR-513 router, which is now end-of-life, poses a severe risk of remote code execution for authenticated users.
Vulnerability
The vulnerability exists within the formEasySetTimezone function of the boa web component, which fails to perform bounds checking on the curTime parameter. By sending a specially crafted HTTP POST request to the /goform/formEasySetTimezone endpoint, an authenticated attacker can trigger a stack-based buffer overflow, leading to potential remote code execution or a denial of service state.
Business impact
Successful exploitation of this vulnerability allows an attacker to achieve remote code execution on the device, potentially gaining full control over the router. Given the device serves as a network gateway, this compromise could facilitate lateral movement into the internal network, interception of traffic, or permanent denial of service. With a CVSS score of 8.8, this flaw represents a high-severity risk to infrastructure integrity and data confidentiality.
Remediation
Immediate Action: As this product is no longer supported by the vendor and no patch is available, the primary remediation is to decommission the device immediately and replace it with a currently supported model.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/formEasySetTimezone endpoint and audit system logs for signs of repeated service crashes or unexpected reboots.
Compensating Controls: If the device cannot be immediately replaced, place it behind a strict firewall that limits administrative access to trusted internal IP addresses only, and employ a Web Application Firewall to filter out malformed or excessively long input parameters.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the technical write-up provided by the researcher (GitHub: Litengzheng/vul_db).
Analyst recommendation
The D-Link DIR-513 is an end-of-life product and will not receive security updates to address this flaw. Organizations currently utilizing this device are at significant risk of compromise. It is strongly recommended to retire these units from production environments as soon as possible to eliminate the exposure, as no software-based mitigation can effectively resolve the underlying architectural weakness.
More D-Link CVEs
Sources
Originally found and disclosed by LtzHust2 (VulDB User), per the CVE Program record.
- VDB-352382 | D-Link DIR-513 boa formEasySetTimezone memory corruption Vulnerability database entry
- VDB-352382 | CTI Indicators (IOB, IOC, IOA)
- Submit #774936 | D-Link DIR-513 1.10 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com