CVE-2026-5979Disclosure(dlink / dir-605l)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Prioritize remediation for dlink dir-605l systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-605l
  • dir-605l_firmware

Threat summary

  • Exploit tooling references are present in monitored signal
  • 4 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
dir-605ldir-605l_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-04-09: 4Exploit Tool / Code · 2026-04-09: 1Technical Details · 2026-04-09: 304-09
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets9 URLs
Full discourse4 posts
  • dbugs@ptdbugs
    Exploit

    D-Link DIR-605L POST Request formVirtualServ buffer overflow CVE: CVE-2026-5979 PT ID: PT-2026-31740 Vendor: D-link Product: DIR-605L CVSS: 8.7 Credits: wxhwxhwxh_mie (VulDB User) Description: A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5979 • https://vuldb.com/vuln/356533 • https://vuldb.com/vuln/356533/cti • https://vuldb.com/submit/791852 • https://lavender-bicycle-a5a.notion.site/D-Link-DIR-605L-formVirtualServ-33153a41781f80b496e1de206077bc7e?source=copy_link • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The post announces a publicly available exploit for a buffer overflow in D‑Link DIR‑605L, supported by technical details and CVSS score, but provides no patch information or evidence of active exploitation.

    00000102
    788 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5979: HIGH] Buffer overflow vulnerability found in D-Link DIR-605L 2.13B01 allows remote attacks through manipulation of argument curTime in formVirtualServ function, impacting unsupported products. ...#cve,CVE-2026-5979,#cybersecurity https://cvefind.com/CVE-2026-5979

    Post summary

    The tweet discloses a buffer overflow CVE-2026-5979 in the D-Link DIR-605L, noting potential for remote attacks via a parameter in formVirtualServ, but lacks PoC, exploit code, patch info, or evidence of active exploitation.

    0000044
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5979 A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the compo… https://www.cve.org/CVERecord?id=CVE-2026-5979 ----- Traducción: CVE-2026-5979 Se … http://infoflow.cloud`

    Post summary

    The post provides a brief disclosure of CVE-2026-5979, noting the vulnerable function in a D-Link router, without mentioning exploitation, patches, or PoC details.

    0000024
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5979 A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the compo… https://www.cve.org/CVERecord?id=CVE-2026-5979

    Post summary

    A new vulnerability (CVE-2026-5979) was identified in D‑Link DIR‑605L firmware 2.13B01, affecting the formVirtualServ function; no additional technical details or mitigation information are supplied.

    00000170
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-605l---
OSdlinkdir-605l_firmware2.13b01--

Explore more