CVE-2026-6014 is a buffer overflow vulnerability in D-Link DIR-513 firmware version 1.10, specifically within the formAdvanceSetup POST request handler. The flaw exists in the webpage parameter of the /goform/formAdvanceSetup function and affects only end-of-life products no longer receiving vendor support. The vulnerability carries a HIGH severity rating with a CVSS score of 8.8, exploitable remotely over the network by authenticated users with low attack complexity. Successful exploitation results in complete system compromise, including high-impact confidentiality, integrity, and availability breaches. While proof-of-concept exploit code has been publicly released, the vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog and shows minimal community engagement. The extremely low EPSS score of 0.0005 indicates negligible real-world exploitation activity at this time, though the published exploit code presents a latent risk if threat actors choose to leverage it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.10CPE matchmatch criteria | cpe:2.3:o:dlink:dir-513_firmware:1.10:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.