CVE-2026-6012: D-Link DIR-513 POST Request formSetPassword buffer overflow
A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6012?
CVE-2026-6012 is classified as a critical vulnerability due to its potential to cause buffer overflow issues.
How do I fix CVE-2026-6012?
To mitigate CVE-2026-6012, you should update the D-Link DIR-513 firmware to the latest version available.
What causes CVE-2026-6012?
CVE-2026-6012 is caused by improper handling of the curTime argument in the formSetPassword function.
Which device is affected by CVE-2026-6012?
CVE-2026-6012 affects the D-Link DIR-513 router running version 1.10.
What are the potential impacts of CVE-2026-6012?
The potential impacts of CVE-2026-6012 include unauthorized access and the possibility of executing arbitrary code.