CVE-2026-4486

A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:dlink:dir-513_firmware:1.10:*:*:*:*:*:*:*
OR cpe:2.3:h:dlink:dir-513:a1:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-513:a2:*:*:*:*:*:*:*

History

03 Apr 2026, 19:35

Type Values Removed Values Added
References () https://github.com/InfiniteLin/Lin-s-CVEdb/blob/main/DIR-513/formEasySetPassword/formEasySetPassword.md - () https://github.com/InfiniteLin/Lin-s-CVEdb/blob/main/DIR-513/formEasySetPassword/formEasySetPassword.md - Exploit, Third Party Advisory
References () https://github.com/InfiniteLin/Lin-s-CVEdb/blob/main/DIR-513/formEasySetPassword/poc.py - () https://github.com/InfiniteLin/Lin-s-CVEdb/blob/main/DIR-513/formEasySetPassword/poc.py - Exploit
References () https://vuldb.com/?ctiid.352009 - () https://vuldb.com/?ctiid.352009 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.352009 - () https://vuldb.com/?id.352009 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.773537 - () https://vuldb.com/?submit.773537 - Issue Tracking, VDB Entry
References () https://vuldb.com/?submit.773566 - () https://vuldb.com/?submit.773566 - Third Party Advisory, VDB Entry
References () https://www.dlink.com/ - () https://www.dlink.com/ - Product
CPE cpe:2.3:h:dlink:dir-513:a2:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dir-513_firmware:1.10:*:*:*:*:*:*:*
cpe:2.3:h:dlink:dir-513:a1:*:*:*:*:*:*:*
CWE CWE-787
First Time Dlink dir-513
Dlink dir-513 Firmware
Dlink
Summary
  • (es) Una vulnerabilidad fue encontrada en D-Link DIR-513 1.10. Esto afecta la función formEasySetPassword del archivo /goform/formEasySetPassword del componente Servicio Web. La manipulación del argumento curTime resulta en desbordamiento de búfer basado en pila. El ataque puede ser realizado desde remoto. El exploit ha sido hecho público y podría ser usado. Esta vulnerabilidad solo afecta productos que ya no son soportados por el mantenedor.

20 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-20 14:16

Updated : 2026-04-03 19:35


NVD link : CVE-2026-4486

Mitre link : CVE-2026-4486

CVE.ORG link : CVE-2026-4486


JSON object : View

Products Affected

dlink

  • dir-513_firmware
  • dir-513
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write