CVE-2026-3978Disclosure(dlink / dir-513)

MEDIUMCVSS 7.4 · HIGH

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Prioritize remediation for dlink dir-513 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formEasySetupWizard3. The manipulation of the argument wan_connected results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-513
  • dir-513_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 9 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked 1d ago at 7 mentions (2026-03-12); latest day: 1
  • 9 total mentions across 3 days

Affected systems

Vendors
Products
dir-513dir-513_firmware

2 versions affected across 2 products

Deep dive

Activity timeline9 mentions / 3d
02457Mentions · 2026-03-11: 1Mentions · 2026-03-12: 7Mentions · 2026-03-13: 1PoC Mentioned / Linked · 2026-03-12: 1Active Exploitation · 2026-03-13: 1Technical Details · 2026-03-12: 503-1103-1203-13
Signal classification4 categories
Disclosure
444.4%
General
333.3%
PoC
111.1%
Active Exploitation
111.1%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-111
General1
2026-03-127
Disclosure4General2PoC1
2026-03-131
Active Exploitation1
Full discourse9 posts
  • EdgeDetectOps@EdgeDetectOps
    Active Exploitation

    Twenty-three minutes after CVE-2026-3978 went public, security researcher Maria Chen watched her honeypot light up. The D-Link DIR-513 vulnerability had barely been cataloged when the first exploitation attempts started hitting vulnerable routers across her network.

    Post summary

    CVE‑2026‑3978 was actively exploited almost immediately after publication, as evidenced by Maria Chen’s honeypot capturing traffic from vulnerable D‑Link DIR‑513 routers.

    1001046
    14 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-3978 - D-Link - DIR-513 - https://www.redpacketsecurity.com/cve-alert-cve-2026-3978-d-link-dir-513/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-3978 #d-link #dir-513

    Post summary

    The tweet announces a CVE alert for CVE-2026-3978 affecting the D-Link DIR-513, linking to an external site for details, but provides no further technical or mitigation information.

    0000075
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3978 - High A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formEasySetupWizard3. The manipulation of the argument wan_connected result... https://www.thehackerwire.com/vulnerability/CVE-2026-3978/ https://t.co/EpqKcyUNdX

    Post summary

    The tweet reports that CVE-2026-3978 was discovered in a D‑Link DIR‑513 router, describing a vulnerability in a specific file and argument manipulation, but provides no PoC, exploit, active use, or remediation details.

    0000028
    134 followersView on X
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-3978 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-3978 #CVE-2026-3978 #CVE #High  #CyberSecurity #InfoSec https://t.co/4W2J7b9scp

    Post summary

    A simple alert announcing CVE-2026-3978, providing only severity information and a link to NVD, with no technical, exploit, or mitigation details.

    0000034
    96 followersView on X
  • dbugs@ptdbugs
    PoC

    D-Link DIR-513 formEasySetupWizard3 stack-based overflow CVE: CVE-2026-3978 Vendor: D-link Product: DIR-513 CVSS: 8.7 Credits: LtzHust2 (VulDB User) Description: A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formEasySetupWizard3. The manipulation of the argument wan_connected results in stack-based buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-3978 • https://vuldb.com/?id.350413 • https://vuldb.com/?ctiid.350413 • https://vuldb.com/?submit.769586 • https://github.com/Litengzheng/vul_db/blob/main/Dir513/vul_21/README.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The D-Link DIR-513 is vulnerable to a stack-based overflow in formEasySetupWizard3 (CVE-2026-3978, CVSS 8.7). A public exploit/PoC is available, though no active exploitation or patch information is reported.

    0000062
    568 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3978 A vulnerability was detected in D-Link DIR-513 1.10. The impacted element is an unknown function of the file /goform/formEasySetupWizard3. The manipulation of the argum… https://www.cve.org/CVERecord?id=CVE-2026-3978

    Post summary

    The brief excerpt reports the existence of CVE‑2026‑3978, noting a vulnerability in the D‑Link DIR‑513 firmware involving an unspecified function of /goform/formEasySetupWizard3, without additional details on exploitation or mitigation.

    00000104
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-3978 - D-Link DIR-513 formEasySetupWizard3 stack-based overflow Intel Report: https://ift.tt/tPZwIr0

    Post summary

    The post announces CVE-2026-3978, a stack-based overflow in the D‑Link DIR‑513 formEasySetupWizard3, and provides a link to an Intel report.

    0000082
    342 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3978: HIGH] Critical vulnerability discovered in D-Link DIR-513 1.10 allows remote attackers to execute a buffer overflow attack via manipulation of the 'wan_connected' argument in /goform/formEasySe...#cve,CVE-2026-3978,#cybersecurity https://cvefind.com/CVE-2026-3978

    Post summary

    The text announces a critical buffer overflow (CVE‑2026‑3978) in the D‑Link DIR‑513 1.10 firmware, enabling remote attackers to execute code by manipulating the 'wan_connected' parameter.

    0000049
    601 followersView on X
  • VulDB 🛡@vuldb
    General

    A severe vulnerability was disclosed for D-Link DIR-513 (CVE-2026-3978) https://vuldb.com/?id.350413

    Post summary

    The statement announces the disclosure of a severe vulnerability (CVE‑2026‑3978) for a D‑Link device, providing only a link for further information without detailing PoC, exploitation, or remediation.

    0000074
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-513---
OSdlinkdir-513_firmware1.10--

Explore more