CVE-2025-10792

HIGH

Dlink Dir-513 Firmware - Out-of-Bounds Write

Title source: rule
STIX 2.1

Description

A security vulnerability has been detected in D-Link DIR-513 A1FW110. Affected is an unknown function of the file /goform/formWPS. Such manipulation of the argument webpage leads to buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. This vulnerability only affects products that are no longer supported by the maintainer.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.325149
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.325149
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.654049
Product product
https://www.dlink.com/

Scores

CVSS v3 8.8
EPSS 0.0227
EPSS Percentile 84.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-120 CWE-787
Status published
Products (1)
dlink/dir-513_firmware 1.10
Published Sep 22, 2025
Tracked Since Feb 18, 2026