CVE-2026-6013

8.8

D-Link · DIR-513

A buffer overflow vulnerability in the D-Link DIR-513 POST request handler allows remote attackers to trigger memory corruption via the curTime argument.

Executive summary

A critical buffer overflow vulnerability in the D-Link DIR-513 router allows for remote code execution and potential system compromise.

Vulnerability

This vulnerability involves a buffer overflow in the formSetRoute function within the /goform/formSetRoute component. Attackers with low-level privileges can trigger this memory corruption remotely by manipulating the curTime argument in a crafted POST request.

Business impact

Successful exploitation of this buffer overflow can lead to complete system compromise, allowing an attacker to execute arbitrary code or cause a denial of service condition. Given the CVSS score of 8.8, this vulnerability poses a significant risk to network integrity and confidentiality, particularly as the device is no longer supported by the vendor, meaning no official security patches will be issued.

Remediation

Immediate Action: Since this device is end-of-life and no patch is available, immediately isolate the affected hardware from the public internet or replace it with a currently supported device.

Proactive Monitoring: Monitor network traffic for unusual POST requests directed at the /goform/formSetRoute endpoint and watch for unexpected device reboots or instability.

Compensating Controls: Implement strict firewall rules to restrict access to the device management interface, ensuring it is only accessible from trusted internal management subnets.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists, as documented in the technical write-up referenced by the vulnerability disclosure.

Analyst recommendation

Due to the lack of vendor support and the availability of public proof-of-concept code, this device represents a severe security liability. Administrators should prioritize the decommissioning of the D-Link DIR-513 in favor of modern, supported networking equipment to ensure adequate protection against remote exploitation.

More D-Link CVEs

Sources

Originally found and disclosed by wxhwxhwxh_mie (VulDB User), per the CVE Program record.