CVE-2026-90699
nicheOS Command Injection via newPin in D-Link DWR-M920 Router Web Interface
D-Link DWR-M920 routers running firmware 1.1.7 contain an OS command injection flaw in the formPinManageSetup handler (/boafrm/formPinManageSetup), where the newPin parameter is passed unsafely to a system command inside function sub_41E60C. A remote attacker who can reach the router's web management interface and authenticate with low-privilege credentials can submit a crafted newPin value to inject and execute arbitrary operating-system commands on the device. Successful exploitation gives the attacker control of the router with the web server's privileges, enabling configuration theft, traffic interception or redirection, and use of the router as a pivot point into attached networks. Only firmware version 1.1.7 of the DWR-M920 is named as affected; other versions may also be vulnerable but were not specified. No confirmed exploitation in the wild or verified public PoC is known, though the advisory language suggests exploit material may be circulating, so the flaw should be treated as exploitable.
What to do: Check D-Link support for a DWR-M920 firmware release newer than 1.1.7 and upgrade if one exists; the device may be end-of-life, in which case plan replacement. In the interim, disable remote/WAN access to the web management interface, restrict management to a trusted LAN or VPN segment, and enforce strong unique admin credentials since exploitation requires authentication. Watch for unexplained reboots, configuration changes, or unknown processes on deployed units.
| D-Link DWR-M920 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.