CVE-2026-4188Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (3 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 3 mentions on most recent observed day (2026-03-16)
  • 6 total mentions across 3 days

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-14: 1Mentions · 2026-03-15: 2Mentions · 2026-03-16: 3PoC Mentioned / Linked · 2026-03-15: 1Exploit Tool / Code · 2026-03-15: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-16: 303-1403-1503-16
Signal classification3 categories
Disclosure
466.7%
Exploit
116.7%
General
116.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-03-141
Disclosure1
2026-03-152
Exploit1General1
2026-03-163
Disclosure3
Full discourse6 posts
  • dbugs@ptdbugs
    Exploit

    D-Link DIR-619L boa formSchedule stack-based overflow CVE: CVE-2026-4188 PT-Identifier: PT-2026-25535 Vendor: D-link Product: DIR-619L CVSS: 8.7 Credits: pjqwudi (VulDB User) Description: A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4188 • https://vuldb.com/?id.351094 • https://vuldb.com/?ctiid.351094 • https://vuldb.com/?submit.769833 • https://github.com/wudipjq/my_vuln/blob/main/D-Link7/vuln_89/89.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    A stack‑based buffer overflow in D‑Link DIR‑619L’s formSchedule function has been disclosed, with a public exploit and PoC available, but no evidence of active exploitation.

    0000183
    613 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4188 - High A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulati... https://www.thehackerwire.com/vulnerability/CVE-2026-4188/ https://t.co/SQgNrzeV4c

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2026‑4188) in D‑Link DIR‑619L routers, describing the affected function but offering no patches, PoC, or evidence of exploitation.

    0000054
    136 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4188: HIGH] Security alert: Vulnerability found in D-Link DIR-619L 2.06B01 allowing remote exploitation via stack-based buffer overflow in boa component. Only affects outdated products.#cve,CVE-2026-4188,#cybersecurity https://cvefind.com/CVE-2026-4188

    Post summary

    The alert announces that D‑Link DIR‑619L firmware 2.06B01 is vulnerable to a stack‑based buffer overflow allowing remote exploitation.

    0000048
    601 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4188 A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa.… https://www.cve.org/CVERecord?id=CVE-2026-4188

    Post summary

    The post announces the discovery of CVE-2026-4188 in D‑Link DIR‑619L, specifying the vulnerable function but providing no PoC, exploit, patch, or active exploitation evidence.

    00000121
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4188 - D-Link DIR-619L boa formSchedule stack-based overflow Intel Report: https://ift.tt/wgE38jq

    Post summary

    A new stack‑based buffer overflow vulnerability (CVE‑2026‑4188) affecting the D‑Link DIR‑619L router has been disclosed, with a report link provided. No evidence of active exploitation, PoC, or patch details is presented.

    0000038
    336 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting D-Link DIR-619L (CVE-2026-4188) https://vuldb.com/?id.351094

    Post summary

    A new vulnerability, CVE‑2026‑4188, affecting the D‑Link DIR‑619L has been announced with its severity increased; the post does not include exploitation details or patch information.

    0000092
    2.1K followersView on X

Explore more