CVE-2026-4486: D-Link DIR-513 Web Service formEasySetPassword stack-based overflow
A vulnerability was found in D-Link DIR-513 1.10. This affects the function formEasySetPassword of the file /goform/formEasySetPassword of the component Web Service. The manipulation of the argument curTime results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4486?
CVE-2026-4486 is considered to have a high severity due to its stack-based overflow vulnerability.
How do I fix CVE-2026-4486?
To mitigate CVE-2026-4486, update the D-Link DIR-513 firmware to the latest version provided by D-Link.
What software is affected by CVE-2026-4486?
CVE-2026-4486 affects the D-Link DIR-513 with firmware version 1.10.
What does CVE-2026-4486 vulnerability exploit?
CVE-2026-4486 exploits the formEasySetPassword function by manipulating the curTime argument.
Can CVE-2026-4486 lead to system compromise?
Yes, CVE-2026-4486 can lead to system compromise due to the nature of stack-based overflows.