ZeroHour

CVE-2026-90702

niche

Authenticated OS Command Injection in D-Link DWR-M921 LTE Router (formDiskFormat)

CVSS 4.0
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-90702 is an OS command injection flaw (CWE-77/CWE-78) in D-Link's DWR-M921 4G LTE router running firmware 1.1.52, located in the system() function reached through the /boafrm/formDiskFormat endpoint of the device's web management interface. A remote attacker submits a disk-format request in which the 'partition' argument is crafted with shell metacharacters; because the value is passed unsanitized to system(), the injected commands execute on the router. The CVSS 4.0 vector (AV:N, PR:H) indicates exploitation requires network access plus high (administrative) privileges on the web UI, so devices still using default or weak admin credentials are at materially greater risk. Successful exploitation gives the attacker full control of the router (VC/VI/VA:H, CVSS 8.5), enabling traffic interception, DNS redirection, or use of the device as a pivot into the local network. The originating VulDB record states the exploit has been published and may be used, although curated PoC trackers list no confirmed public PoC, the flaw is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation to date.

What to do: Check D-Link's security advisories for a fixed DWR-M921 firmware release and upgrade if one is available (no patched version is identified in this record, and the hardware line is aging). Immediately disable remote/WAN access to the web management interface (which exposes /boafrm/formDiskFormat), restrict management to the LAN or a dedicated firewall rule, and replace any default admin credentials. Monitor the device for unexpected configuration changes or outbound traffic, and consider isolating or retiring end-of-life routers that cannot be patched.

Affected
D-Link DWR-M921
Estimated exposure
nichelikely hundreds to low thousands of internet-exposed devices (estimate) — The DWR-M921 is an older consumer/SMB 4G LTE router with no published install or sales counts, and publicly scannable D-Link Boa-based routers of this class typically show exposure in the hundreds to low thousands, so this is a best-effort…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.

Weakness
CWE-77, CWE-78
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.