Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5984

31
FAUCET Score

CVE-2026-5984 is a buffer overflow vulnerability in the formSetLog function of D-Link DIR-605L router firmware version 2.13B01, specifically in the /goform/formSetLog POST request handler. The vulnerability is triggered through manipulation of the curTime parameter and affects only end-of-life products no longer supported by the manufacturer. The vulnerability carries a CVSS score of 8.8 (HIGH), with a network-accessible attack vector that requires low complexity and low privileges, but no user interaction. Successful exploitation could result in complete system compromise, including high impact to confidentiality, integrity, and availability of affected devices. Public exploit code is available for this vulnerability, though it is not currently listed in CISA's Known Exploited Vulnerabilities catalog and shows no signs of active exploitation in the wild. The EPSS score of 0.00021 indicates extremely low probability of exploitation in practice, likely due to the limited installed base of unsupported legacy hardware and the availability of security updates or product replacements.

Impacted Technologies

VendorProductVersion(s)CPE
2.13b01CPE matchmatch criteria
cpe:2.3:o:dlink:dir-605l_firmware:2.13b01:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

7.4HIGH

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.78%
Probability of exploitation in next 30 days
EPSS Percentile
52.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0078 is in the 46th percentile among its peer group of 17,822 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

lavender-bicycle-a5a.notion.site / D-Link-DIR-605L-formSetLog-33153a41781f8038bbbcc04073d7875b
ExploitThird Party Advisory
vuldb.com / submit/791857
Third Party AdvisoryVDB Entry
vuldb.com / vuln/356538
Third Party AdvisoryVDB Entry
vuldb.com / vuln/356538/cti
Permissions RequiredVDB Entry
dlink.com
Product