CVE-2026-5980Disclosure(dlink / dir-605l)

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-605l
  • dir-605l_firmware

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Exploit: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-04-09); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
dir-605ldir-605l_firmware

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-09: 3Mentions · 2026-04-10: 1PoC Mentioned / Linked · 2026-04-10: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 104-0904-10
Signal classification2 categories
Disclosure
375.0%
Exploit
125.0%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-04-093
Disclosure3
2026-04-101
Exploit1
Full discourse4 posts
  • dbugs@ptdbugs
    Exploit

    D-Link DIR-605L POST Request formSetMACFilter buffer overflow CVE: CVE-2026-5980 PT ID: PT-2026-31741 Vendor: D-link Product: DIR-605L CVSS: 8.7 Credits: wxhwxhwxh_mie (VulDB User) Description: A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Request Handler. This manipulation of the argument curTime causes buffer overflow. The attack may be initiated remotely. The exploit has been published and may be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-5980 • https://vuldb.com/vuln/356534 • https://vuldb.com/vuln/356534/cti • https://vuldb.com/submit/791853 • https://lavender-bicycle-a5a.notion.site/D-Link-DIR-605L-formSetMACFilter-33153a41781f807c8fb4c3a75f7b555e?source=copy_link • https://www.dlink.com/ #dbugs_vuln

    Post summary

    The post discloses a remote buffer overflow in D-Link DIR-605L with published exploit references, but no active exploitation or patch information is provided.

    0000076
    788 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-5980: HIGH] Critical vulnerability discovered in D-Link DIR-605L 2.13B01 allows remote attackers to exploit a buffer overflow through formSetMACFilter. Affected products are no longer supported.#cve,CVE-2026-5980,#cybersecurity https://cvefind.com/CVE-2026-5980

    Post summary

    CVE‑2026‑5980 is a high‑severity buffer overflow in D‑Link DIR‑605L’s formSetMACFilter; no PoC, exploit, or active exploitation is mentioned, and only the discontinuation of support is noted.

    0000059
    619 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-5980 A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Req… https://www.cve.org/CVERecord?id=CVE-2026-5980 ----- Traducción: CVE-2026-5980 Se … http://infoflow.cloud`

    Post summary

    A new vulnerability, CVE-2026-5980, has been announced for the D‑Link DIR‑605L router, affecting the formSetMACFilter function. No PoC, exploit, or patch information is provided.

    0000022
    67 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-5980 A flaw has been found in D-Link DIR-605L 2.13B01. Affected by this issue is the function formSetMACFilter of the file /goform/formSetMACFilter of the component POST Req… https://www.cve.org/CVERecord?id=CVE-2026-5980

    Post summary

    A newly discovered flaw (CVE‑2026‑5980) in the D‑Link DIR‑605L router’s formSetMACFilter function is disclosed, with no PoC, exploit, or patch information provided.

    00000122
    57.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-605l---
OSdlinkdir-605l_firmware2.13b01--

Explore more