CVE-2026-4555Disclosure(dlink / dir-513)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dir-513 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-121CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-513
  • dir-513_firmware

Threat summary

  • Public PoC and exploit tooling are both present
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-22); latest day: 2
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
dir-513dir-513_firmware

2 versions affected across 2 products

Deep dive

Activity timeline7 mentions / 3d
01234Mentions · 2026-03-21: 1Mentions · 2026-03-22: 4Mentions · 2026-03-23: 2PoC Mentioned / Linked · 2026-03-22: 2Exploit Tool / Code · 2026-03-22: 1Technical Details · 2026-03-22: 4Technical Details · 2026-03-23: 103-2103-2203-23
Signal classification2 categories
Disclosure
571.4%
Exploit
228.6%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-03-211
Disclosure1
2026-03-224
Disclosure2Exploit2
2026-03-232
Disclosure2
Full discourse7 posts
  • dbugs@ptdbugs
    Exploit

    D-Link DIR-513 boa formEasySetTimezone memory corruption CVE: CVE-2026-4555 PT-Identifier: PT-2026-26945 Vendor: D-link Product: DIR-513 CVSS: 8.7 Credits: LtzHust2 (VulDB User) Description: A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4555 • https://vuldb.com/?id.352382 • https://vuldb.com/?ctiid.352382 • https://vuldb.com/?submit.774936 • https://github.com/Litengzheng/vul_db/blob/main/Dir513/vul_24/README.md • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The CVE-2026-4555 vulnerability in D‑Link DIR‑513 is a stack-based buffer overflow in formEasySetTimezone; a public exploit exists, but no patch or active exploitation evidence is reported.

    01000147
    696 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4555 A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component… https://www.cve.org/CVERecord?id=CVE-2026-4555

    Post summary

    The post announces a newly identified weakness in D-Link DIR‑513 firmware, specifying the affected function and file path, but does not provide any proof of concept, exploit tool, or mitigation details.

    0000092
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-4555 - D-Link - DIR-513 - https://www.redpacketsecurity.com/cve-alert-cve-2026-4555-d-link-dir-513/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-4555 #d-link #dir-513

    Post summary

    The tweet announces the CVE-2026-4555 vulnerability impacting D-Link DIR-513 and links to an external alert page for further information, but provides no PoC, exploit code, or detailed technical or mitigation details.

    0000086
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-4555 - High A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation ... https://www.thehackerwire.com/vulnerability/CVE-2026-4555/ https://t.co/NZMgdrL6Jb

    Post summary

    A vulnerability in D-Link DIR-513 firmware (CVE‑2026‑4555) is disclosed, affecting the formEasySetTimezone function, but no PoC, exploit, or patch details are included.

    0000042
    144 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4555 - D-Link DIR-513 boa formEasySetTimezone memory corruption Intel Report: https://ift.tt/xXTjAY7

    Post summary

    The alert announces CVE-2026-4555, a memory‑corruption vulnerability in the D-Link DIR‑513, and links to an Intel report for further information.

    0000036
    292 followersView on X
  • CVEFind.com@CveFindCom
    Exploit

    [CVE-2026-4555: HIGH] Critical vulnerability in D-Link DIR-513 1.10's formEasySetTimezone function could lead to remote attacks via stack-based buffer overflow. Public exploit available for unsupported products.#cve,CVE-2026-4555,#cybersecurity https://cvefind.com/CVE-2026-4555

    Post summary

    A high‑severity stack‑based buffer overflow in D‑Link DIR‑513’s formEasySetTimezone function has been disclosed, and a public exploit is available for unsupported devices, though no patch or detailed exploit code is provided.

    0000047
    605 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A new vulnerability with increased severity was disclosed for D-Link DIR-513 (CVE-2026-4555) https://vuldb.com/?id.352382

    Post summary

    A new high‑severity vulnerability (CVE‑2026‑4555) affecting the D-LINK DIR‑513 was disclosed, with a reference to a vulnerability database entry.

    0000064
    2.1K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-513---
OSdlinkdir-513_firmware1.10--

Explore more