HIGH
D-Link DIR-513 POST Request formAdvanceSetup buffer overflow
Published Apr 10, 2026
8.7
HIGHCVSS 4.0
EPSS 1.16%
Description
A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected products
-
- Version 1.10StatusaffectedConstraints-
- Version
AND
- 1.10
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21310 Advisory
- https://lavender-bicycle-a5a.notion.site/D-Link-DIR-513-formAdvanceSetup-33153a41781f80829d47ec9b86dd8abf?source=copy_link exploitThird Party Advisory
- https://vuldb.com/submit/791860 third-party-advisoryThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/356570 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/vuln/356570/cti signaturepermissions-requiredPermissions RequiredVDB Entry
- https://www.dlink.com/ product
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-21310 | Advisory | |
| https://lavender-bicycle-a5a.notion.site/D-Link-DIR-513-formAdvanceSetup-33153a41781f80829d47ec9b86dd8abf?source=copy_link | exploitThird Party Advisory | |
| https://vuldb.com/submit/791860 | third-party-advisoryThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/356570 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/vuln/356570/cti | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://www.dlink.com/ | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Apr 10, 2026
Updated Apr 10, 2026
Reserved Apr 9, 2026
Link CVE-2026-6014
CISA Vulnrichment
Updated Apr 10, 2026
ENISA EUVD
EUVD-2026-21310 Assigner VulDB
Published Apr 10, 2026
Updated Apr 10, 2026
Exploited since n/a
Link EUVD-2026-21310