CVE-2026-5979: D-Link DIR-605L POST Request formVirtualServ buffer overflow
A vulnerability was detected in D-Link DIR-605L 2.13B01. Affected by this vulnerability is the function formVirtualServ of the file /goform/formVirtualServ of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack can be launched remotely. The exploit is now public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5979?
The severity of CVE-2026-5979 is classified as high due to the potential buffer overflow vulnerability that can allow remote code execution.
How do I fix CVE-2026-5979?
To fix CVE-2026-5979, update the D-Link DIR-605L firmware to the latest version available from the manufacturer.
What component of the D-Link DIR-605L is affected by CVE-2026-5979?
CVE-2026-5979 affects the POST Request Handler specifically in the function formVirtualServ.
Can CVE-2026-5979 be exploited remotely?
Yes, CVE-2026-5979 can be exploited remotely, allowing attackers to execute arbitrary code on the device.
Which versions of D-Link DIR-605L are vulnerable to CVE-2026-5979?
D-Link DIR-605L version 2.13B01 is specifically vulnerable to CVE-2026-5979.