CVE-2026-6013
8.8D-Link · DIR-513
A buffer overflow vulnerability in the D-Link DIR-513 POST request handler allows remote attackers to trigger memory corruption via the curTime argument.
Executive summary
A critical buffer overflow vulnerability in the D-Link DIR-513 router allows for remote code execution and potential system compromise.
Vulnerability
This vulnerability involves a buffer overflow in the formSetRoute function within the /goform/formSetRoute component. Attackers with low-level privileges can trigger this memory corruption remotely by manipulating the curTime argument in a crafted POST request.
Business impact
Successful exploitation of this buffer overflow can lead to complete system compromise, allowing an attacker to execute arbitrary code or cause a denial of service condition. Given the CVSS score of 8.8, this vulnerability poses a significant risk to network integrity and confidentiality, particularly as the device is no longer supported by the vendor, meaning no official security patches will be issued.
Remediation
Immediate Action: Since this device is end-of-life and no patch is available, immediately isolate the affected hardware from the public internet or replace it with a currently supported device.
Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/formSetRoute endpoint and watch for unexpected device reboots or instability.
Compensating Controls: Implement strict firewall rules to restrict access to the device management interface, ensuring it is only accessible from trusted internal management subnets.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the technical write-up referenced by the vulnerability disclosure.
Analyst recommendation
Due to the lack of vendor support and the availability of public proof-of-concept code, this device represents a severe security liability. Administrators should prioritize the decommissioning of the D-Link DIR-513 in favor of modern, supported networking equipment to ensure adequate protection against remote exploitation.
More D-Link CVEs
Sources
Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.
- VDB-356569 | D-Link DIR-513 POST Request formSetRoute buffer overflow Vulnerability database entry
- VDB-356569 | CTI Indicators (IOB, IOC, IOA)
- Submit #791859 | D-Link DIR-513 D-Link DIR-513 A2 1.10 Buffer Overflow Third-party advisory
- Exploit / PoC
- dlink.com