📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global phishing Financial Services, Technology, Multiple Sectors CRITICAL 5h Global insider Education HIGH 23h Global supply_chain Software Development and Technology HIGH 1d Global apt Government/Critical Infrastructure CRITICAL 1d Global vulnerability Enterprise Software / Data Analytics CRITICAL 1d Global vulnerability Artificial Intelligence and Technology HIGH 1d Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 2d Global phishing Financial Services, Technology, Multiple Sectors CRITICAL 5h Global insider Education HIGH 23h Global supply_chain Software Development and Technology HIGH 1d Global apt Government/Critical Infrastructure CRITICAL 1d Global vulnerability Enterprise Software / Data Analytics CRITICAL 1d Global vulnerability Artificial Intelligence and Technology HIGH 1d Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 2d Global phishing Financial Services, Technology, Multiple Sectors CRITICAL 5h Global insider Education HIGH 23h Global supply_chain Software Development and Technology HIGH 1d Global apt Government/Critical Infrastructure CRITICAL 1d Global vulnerability Enterprise Software / Data Analytics CRITICAL 1d Global vulnerability Artificial Intelligence and Technology HIGH 1d Global general Technology and Artificial Intelligence MEDIUM 1d Global general Technology and Artificial Intelligence HIGH 1d Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 2d
Vulnerabilities

CVE-2026-6012

High
CWE-119 — Weakness Type
Published: Apr 10, 2026  ·  Modified: Apr 17, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

🤖 AI Executive Summary

A critical buffer overflow vulnerability (CVE-2026-6012) exists in D-Link DIR-513 1.10 routers affecting the password setting function. With a CVSS score of 8.8, this allows remote attackers to execute arbitrary code by manipulating the curTime parameter. Since D-Link has discontinued support for this product line, no patches are available, making this a persistent threat for organizations still operating legacy equipment.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 23, 2026 09:03
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi organizations, particularly: (1) Government agencies and NCA-regulated entities using legacy D-Link routers for network perimeter defense; (2) Banking sector (SAMA-regulated) if DIR-513 devices are deployed in branch offices or remote access points; (3) Telecommunications providers (STC, Mobily) managing legacy network infrastructure; (4) Healthcare facilities using outdated networking equipment; (5) Energy sector (ARAMCO, utilities) with legacy industrial control network segments. The lack of vendor support and public exploit availability make this especially critical for organizations unable to immediately replace affected hardware.
🏢 Affected Saudi Sectors
Government and Public Administration Banking and Financial Services Telecommunications Healthcare Energy and Utilities Education Retail and E-commerce
⚖️ Saudi Risk Score (AI)
8.5
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Conduct urgent inventory of all D-Link DIR-513 1.10 devices across the organization
2. Isolate affected routers from critical network segments if replacement is not immediately possible
3. Implement network segmentation to limit exposure of DIR-513 devices
4. Disable remote management features (SSH, HTTP/HTTPS admin access) if not essential
5. Restrict access to /goform/formSetPassword endpoint using firewall rules

Patching Guidance:
- No vendor patch available; immediate hardware replacement is the only permanent solution
- Prioritize replacement of DIR-513 devices in critical infrastructure roles
- Upgrade to current D-Link models with active security support

Compensating Controls:
1. Deploy Web Application Firewall (WAF) rules to block POST requests to /goform/formSetPassword with suspicious curTime parameters
2. Implement intrusion detection signatures monitoring for buffer overflow attempts
3. Enable comprehensive logging and monitoring of all administrative access attempts
4. Deploy network-based IPS/IDS with signatures for DIR-513 exploitation attempts
5. Implement strict access controls limiting administrative access to trusted IP ranges only
6. Monitor for signs of compromise: unexpected password changes, unauthorized configuration modifications, unusual network traffic patterns

Detection Rules:
- Alert on POST requests to /goform/formSetPassword with curTime parameter values exceeding normal length (>32 bytes)
- Monitor for multiple failed authentication attempts followed by successful access
- Track configuration file modifications on affected devices
- Alert on unexpected firmware version changes or device resets
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. إجراء جرد عاجل لجميع أجهزة D-Link DIR-513 الإصدار 1.10 في المنظمة
2. عزل الأجهزة المتأثرة عن أجزاء الشبكة الحرجة إذا لم يكن الاستبدال ممكناً فوراً
3. تطبيق تقسيم الشبكة لتحديد تعرض أجهزة DIR-513
4. تعطيل ميزات الإدارة البعيدة (SSH، HTTP/HTTPS) إذا لم تكن ضرورية
5. تقييد الوصول إلى نقطة نهاية /goform/formSetPassword باستخدام قواعد جدار الحماية

إرشادات التصحيح:
- لا يوجد تصحيح من المورد؛ استبدال الأجهزة الفوري هو الحل الدائم الوحيد
- أولويات استبدال أجهزة DIR-513 في أدوار البنية التحتية الحرجة
- الترقية إلى نماذج D-Link الحالية مع دعم أمان نشط

الضوابط البديلة:
1. نشر قواعد جدار تطبيقات الويب (WAF) لحجب طلبات POST إلى /goform/formSetPassword بمعاملات curTime مريبة
2. تطبيق توقيعات كشف الاختراق لمراقبة محاولات تجاوز المخزن المؤقت
3. تفعيل السجلات الشاملة ومراقبة جميع محاولات الوصول الإداري
4. نشر نظام منع/كشف الاختراق على مستوى الشبكة مع توقيعات استغلال DIR-513
5. تطبيق ضوابط وصول صارمة تقصر الوصول الإداري على نطاقات IP الموثوقة فقط
6. مراقبة علامات الاختراق: تغييرات كلمات المرور غير المتوقعة، تعديلات التكوين غير المصرح بها، أنماط حركة الشبكة غير العادية

قواعد الكشف:
- تنبيه على طلبات POST إلى /goform/formSetPassword مع قيم معامل curTime تتجاوز الطول الطبيعي (>32 بايت)
- مراقبة محاولات المصادقة الفاشلة المتعددة متبوعة بوصول ناجح
- تتبع تعديلات ملفات التكوين على الأجهزة المتأثرة
- تنبيه على تغييرات إصدار البرنامج الثابت غير المتوقعة أو إعادة تعيين الجهاز
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.8.1 - Asset Management and Inventory Control ECC 2024 A.8.2 - Information and Other Assets ECC 2024 A.13.1 - Network Security ECC 2024 A.14.2 - System Development and Maintenance ECC 2024 A.12.6 - Management of Technical Vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.AM-1 - Physical Devices and Software Assets SAMA CSF PR.DS-1 - Data Security Management SAMA CSF PR.IP-1 - Security Policy and Process SAMA CSF DE.CM-1 - Detection Processes SAMA CSF RS.MI-1 - Incident Response and Management
🟡 ISO 27001:2022
ISO 27001:2022 A.5.9 - Access Control ISO 27001:2022 A.8.1 - Asset Management ISO 27001:2022 A.8.2 - Information Classification ISO 27001:2022 A.12.6 - Management of Technical Vulnerabilities ISO 27001:2022 A.14.2 - System Development and Maintenance
🟣 PCI DSS v4.0.1
PCI DSS 1.1 - Firewall Configuration Standards PCI DSS 2.1 - Default Passwords and Security Parameters PCI DSS 6.2 - Security Patches and Updates PCI DSS 11.2 - Vulnerability Scanning
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-119
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-04-10
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
8.5
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-119
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.