CVE-2026-4486Disclosure(dlink / dir-513)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dir-513 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-513
  • dir-513_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-21); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
dir-513dir-513_firmware

3 versions affected across 2 products

Deep dive

Activity timeline6 mentions / 3d
01223Mentions · 2026-03-20: 2Mentions · 2026-03-21: 3Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-21: 1Exploit Tool / Code · 2026-03-21: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-21: 2Technical Details · 2026-03-22: 103-2003-2103-22
Signal classification1 categories
Disclosure
6100.0%
Referenced assets12 URLs
Classification over time
DateTotalLabels
2026-03-202
Disclosure2
2026-03-213
Disclosure3
2026-03-221
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-4486 A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. Th… https://www.cve.org/CVERecord?id=CVE-2026-4486

    Post summary

    A vulnerability affecting the formEasySetPassword function in D-Link DIR‑513’s web service is documented (CVE‑2026‑4486), but no PoC, exploit, or mitigation details are provided.

    0000097
    56.8K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    The severity is increased for this new vulnerability affecting D-Link DIR-513 (CVE-2026-4486) https://vuldb.com/?id.352009

    Post summary

    The post announces that severity has been increased for a newly identified vulnerability, CVE‑2026‑4486, affecting the D‑Link DIR‑513 router, without providing exploit or mitigation details.

    0000054
    2.1K followersView on X
  • dbugs@ptdbugs
    Disclosure

    D-Link DIR-513 Web Service formEasySetPassword stack-based overflow CVE: CVE-2026-4486 PT-Identifier: PT-2026-26619 Vendor: D-link Product: DIR-513 CVSS: 8.7 Credits: AttackingLin (VulDB User) Description: A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4486 • https://vuldb.com/?id.352009 • https://vuldb.com/?ctiid.352009 • https://vuldb.com/?submit.773537 • https://vuldb.com/?submit.773566 • https://github.com/InfiniteLin/Lin-s-CVEdb/blob/main/DIR-513/formEasySetPassword/formEasySetPassword.md • https://github.com/InfiniteLin/Lin-s-CVEdb/blob/main/DIR-513/formEasySetPassword/poc.py • https://www.dlink.com/ #dbugs_vuln

    Post summary

    D-Link DIR‑513 is affected by a stack‑based buffer overflow in formEasySetPassword; the vulnerability is publicly disclosed with PoC code, but no patches or active exploitation are reported.

    0000079
    649 followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4486 - D-Link - DIR-513 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4486-d-link-dir-513/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4486 #d-link #dir-513

    Post summary

    The tweet announces a CVE Alert for CVE-2026-4486 affecting the D-Link DIR‑513 and provides a link to a RedPacketSecurity advisory, but offers no technical, exploit, or mitigation details.

    0000060
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4486 - High A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the ar... https://www.thehackerwire.com/vulnerability/CVE-2026-4486/ https://t.co/U2pPB4Fu9o

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑4486) in D‑Link DIR‑513, detailing the affected function and component.

    0000042
    138 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-4486: HIGH] Critical stack-based buffer overflow vulnerability found in D-Link DIR-513 1.10. Exploit public, could be used remotely. Affects unsupported products.#cve,CVE-2026-4486,#cybersecurity https://cvefind.com/CVE-2026-4486

    Post summary

    A new high‑severity stack‑based buffer overflow (CVE‑2026‑4486) has been disclosed for the D-Link DIR‑513 1.10, with a publicly available exploit that can be used remotely, but no patch or active exploitation details are provided.

    0000042
    604 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-513a1--
HWdlinkdir-513a2--
OSdlinkdir-513_firmware1.10--

Explore more