CVE-2026-5024: high-severity vulnerability in D-Link DIR-513
D-Link DIR-513 formSetEmail stack-based overflow
Published · Updated
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.7epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
A vulnerability was found in D-Link DIR-513 1.10. This issue affects the function formSetEmail of the file /goform/formSetEmail. Performing a manipulation of the argument curTime results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used. This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P
Affected products
D-Link · DIR-513public PoCs found — 1
cve_referencegithub.com/Litengzheng/vul_db/blob/main/Dir513/vul_30/README.mdunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Related CVEs — D-Link DIR-513
In the same product, most dangerous first.
CVE-2025-8159HIGHD-Link DIR-513 HTTP POST Request formLanguageChange stack-based overflowEPSS 16.7%CVE-2025-8184HIGHD-Link DIR-513 HTTP POST Request formSetWanL2TPtriggers formSetWanL2TPcallback stack-based overflowEPSS 10.5%CVE-2025-7945HIGHD-Link DIR-513 formSetWanDhcpplus buffer overflowEPSS 5.7%CVE-2026-4465MEDIUMD-Link DIR-513 formSysCmd os command injectionEPSS 5.0%CVE-2025-10792HIGHD-Link DIR-513 formWPS buffer overflowEPSS 3.2%CVE-2025-8169HIGHD-Link DIR-513 HTTP POST Request formSetWanPPTPpath formSetWanPPTPcallback buffer overflowEPSS 1.7%