CVE-2026-5984 is a buffer overflow vulnerability in the formSetLog function of D-Link DIR-605L router firmware version 2.13B01, specifically in the /goform/formSetLog POST request handler. The vulnerability is triggered through manipulation of the curTime parameter and affects only end-of-life products no longer supported by the manufacturer. The vulnerability carries a CVSS score of 8.8 (HIGH), with a network-accessible attack vector that requires low complexity and low privileges, but no user interaction. Successful exploitation could result in complete system compromise, including high impact to confidentiality, integrity, and availability of affected devices. Public exploit code is available for this vulnerability, though it is not currently listed in CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.00021 indicates extremely low probability of exploitation in practice, likely due to the limited installed base of unsupported legacy hardware and the availability of security updates or product replacements.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.13b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-605l_firmware:2.13b01:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.