CVE-2026-6012Disclosure(dlink / dir-513)

LOWCVSS 7.4 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-119CWE-120

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • dir-513
  • dir-513_firmware

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 5 classified signals
  • Peaked 1d ago at 4 mentions (2026-04-10); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
dir-513dir-513_firmware

2 versions affected across 2 products

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-10: 4Mentions · 2026-04-11: 1Technical Details · 2026-04-10: 304-1004-11
Signal classification1 categories
Disclosure
5100.0%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-04-104
Disclosure4
2026-04-111
Disclosure1
Full discourse5 posts
  • dbugs@ptdbugs
    Disclosure

    D-Link DIR-513 POST Request formSetPassword buffer overflow CVE: CVE-2026-6012 PT ID: PT-2026-31872 Vendor: D-link Product: DIR-513 CVSS: 8.7 Credits: wxhwxhwxh_mie (VulDB User) Description: A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-6012 • https://vuldb.com/vuln/356568 • https://vuldb.com/vuln/356568/cti • https://vuldb.com/submit/791858 • https://lavender-bicycle-a5a.notion.site/D-Link-DIR-513-formSetPassword-33153a41781f806e9a3cf63a5a9091ac?source=copy_link • https://www.dlink.com/ #dbugs_vuln

    Post summary

    A buffer overflow vulnerability (CVE-2026-6012) in the D‑Link DIR‑513’s formSetPassword function is disclosed, with technical details provided but no proof‑of‑concept, active exploitation, or remediation information.

    00010108
    788 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6012 📊 Severity: 8.8 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6012 #CVE-2026-6012 #CVE #High #CyberSecurity #InfoSec https://t.co/1zQ6pDCQ1G

    Post summary

    The tweet reports a new CVE (CVE‑2026‑6012) with a severity rating of 8.8 but provides no technical details, exploit information, or mitigation guidance.

    0000039
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6012 A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST R… https://www.cve.org/CVERecord?id=CVE-2026-6012

    Post summary

    A new vulnerability, CVE-2026-6012, has been identified in D‑Link DIR‑513 1.10, affecting the formSetPassword function. The notice provides only a brief description and a reference to the CVE record.

    00000102
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6012 Buffer Overflow in D-Link DIR-513 1.10 POST Request Handler formSetPassword https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6012

    Post summary

    The post reports a buffer‑overflow vulnerability (CVE‑2026‑6012) affecting the formSetPassword handler in D‑Link DIR‑513 firmware 1.10, with a link to a vulnerability detail page.

    0000048
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-6012: HIGH] Security alert: Vulnerability in D-Link DIR-513 1.10 discovered! Exploit allows remote buffer overflow via manipulation of curTime argument in formSetPassword function. Products no longer...#cve,CVE-2026-6012,#cybersecurity https://cvefind.com/CVE-2026-6012

    Post summary

    The post announces a high‑severity remote buffer overflow vulnerability in D‑Link DIR‑513, providing a brief technical description but no proof of concept, exploit code, or patches.

    0000034
    619 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWdlinkdir-513a2--
OSdlinkdir-513_firmware1.10--

Explore more