CVE-2026-5024
8.8D-Link · DIR-513
A stack-based buffer overflow in the D-Link DIR-513 formSetEmail function allows remote attackers to trigger memory corruption and potential code execution via a crafted HTTP POST request.
Executive summary
A critical stack-based buffer overflow in D-Link DIR-513 routers, which are no longer supported, allows remote attackers to achieve arbitrary code execution or cause a denial of service.
Vulnerability
The vulnerability exists within the formSetEmail function located at the /goform/formSetEmail endpoint. By manipulating the curTime argument, an attacker with low privileges can trigger a stack-based buffer overflow due to a lack of length validation when processing user-provided input.
Business impact
Successful exploitation of this vulnerability permits remote code execution, granting an attacker full control over the affected routing device. Given the device's role in network traffic management, this could lead to total compromise of internal network traffic, unauthorized access to connected resources, and severe reputational damage. The CVSS score of 8.8 reflects the high severity of this flaw, which is exacerbated by the fact that the product is end-of-life and will not receive vendor patches.
Remediation
Immediate Action: Because the vendor no longer supports this device and no patch is available, the most effective remediation is to decommission and replace the affected D-Link DIR-513 hardware with a currently supported alternative.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/formSetEmail endpoint, which may indicate attempted exploitation.
Compensating Controls: If immediate replacement is not feasible, isolate the device from the public internet using a firewall or VLAN and restrict access to the administrative interface to trusted internal management segments.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists as documented in the research write-up by Li Tengzheng.
Analyst recommendation
The risk posed by CVE-2026-5024 is substantial, particularly because D-Link has ceased support for the DIR-513, meaning no official firmware update will be released to address the overflow. Organizations currently utilizing this equipment must prioritize its immediate removal from the network. Continued use of this device constitutes a significant security liability that cannot be fully mitigated by standard defensive configurations.
More D-Link CVEs
Sources
Originally found and disclosed by LtzHust2 (VulDB User), per the CVE Program record.
- VDB-353908 | D-Link DIR-513 formSetEmail stack-based overflow Vulnerability database entry
- VDB-353908 | CTI Indicators (IOB, IOC, IOA)
- Submit #778414 | D-Link DIR-513 1.10 Stack-based Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com