CVE-2026-6012

8.8

D-Link · DIR-513

A buffer overflow vulnerability in the formSetPassword function of D-Link DIR-513 allows remote attackers to trigger memory corruption via the curTime argument.

Executive summary

A critical buffer overflow vulnerability in the D-Link DIR-513 router allows for remote code execution, posing a significant risk to network security.

Vulnerability

This vulnerability is a buffer overflow (CWE-120) located within the formSetPassword function of the POST request handler. An authenticated attacker can trigger this memory corruption remotely by manipulating the curTime argument.

Business impact

Successful exploitation of this vulnerability can lead to a complete compromise of the affected router, potentially allowing an attacker to gain unauthorized control over network traffic. Given the high CVSS score of 8.8, this represents a severe threat to confidentiality, integrity, and availability within the local network. Organizations relying on this end of life hardware face elevated risks, as the vendor no longer provides security updates for the device.

Remediation

Immediate Action: Since the vendor has confirmed this product is no longer supported, the primary remediation is to retire and replace the affected hardware with a current, supported device.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/formSetPassword endpoint and investigate any unexpected device reboots or service instability.

Compensating Controls: Implement strict network segmentation to isolate the vulnerable device from critical segments and deploy a Web Application Firewall or Intrusion Prevention System to detect and block malicious payloads targeting buffer overflow patterns.

Exploitation status

Public Exploit Available: Yes, a public proof of concept is available via the technical write-up referenced at the provided Notion security research link.

Analyst recommendation

The D-Link DIR-513 is legacy hardware that no longer receives security maintenance, making it a permanent liability in any production environment. We strongly recommend immediate decommissioning of these devices to prevent potential remote exploitation. If immediate replacement is not feasible, restrict administrative access to the device to the absolute minimum number of trusted internal hosts and monitor all associated traffic for signs of compromise.

More D-Link CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.