CVE-2026-4188: D-Link DIR-619L boa formSchedule stack-based overflow
A security flaw has been discovered in D-Link DIR-619L 2.06B01. The affected element is the function formSchedule of the file /goform/formSchedule of the component boa. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4188?
CVE-2026-4188 is categorized as a critical vulnerability due to its potential to allow remote code execution through stack-based buffer overflow.
How do I fix CVE-2026-4188?
To mitigate CVE-2026-4188, it is recommended to update the D-Link DIR-619L firmware to the latest version provided by the manufacturer.
What components are affected by CVE-2026-4188?
CVE-2026-4188 affects the boa component specifically within the formSchedule function of D-Link DIR-619L routers.
Can CVE-2026-4188 be exploited remotely?
Yes, CVE-2026-4188 can be exploited remotely if the attacker can manipulate the curTime argument.
What impact does CVE-2026-4188 have on affected devices?
The exploitation of CVE-2026-4188 can lead to unauthorized access, data leakage, and remote code execution on affected devices.