CVE-2026-5979 is a buffer overflow vulnerability affecting D-Link DIR-605L version 2.13B01 in the POST Request Handler's formVirtualServ function, specifically when the curTime argument is manipulated. This vulnerability impacts only legacy, unsupported D-Link routers. The flaw enables remote exploitation with a CVSS score of 8.8 (HIGH), requiring only low-complexity attacks with valid user credentials and granting attackers high-impact access including complete confidentiality, integrity, and availability compromise. Public exploit code is available for this vulnerability; however, it is not currently listed on CISA's Known Exploited Vulnerabilities catalog and shows no evidence of active exploitation in the wild. Given the product's end-of-life status and minimal community attention, the immediate risk remains low despite the technical severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.13b01CPE matchmatch criteria | cpe:2.3:o:dlink:dir-605l_firmware:2.13b01:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.