CVE-2026-90702
nicheAuthenticated OS Command Injection in D-Link DWR-M921 LTE Router (formDiskFormat)
CVE-2026-90702 is an OS command injection flaw (CWE-77/CWE-78) in D-Link's DWR-M921 4G LTE router running firmware 1.1.52, located in the system() function reached through the /boafrm/formDiskFormat endpoint of the device's web management interface. A remote attacker submits a disk-format request in which the 'partition' argument is crafted with shell metacharacters; because the value is passed unsanitized to system(), the injected commands execute on the router. The CVSS 4.0 vector (AV:N, PR:H) indicates exploitation requires network access plus high (administrative) privileges on the web UI, so devices still using default or weak admin credentials are at materially greater risk. Successful exploitation gives the attacker full control of the router (VC/VI/VA:H, CVSS 8.5), enabling traffic interception, DNS redirection, or use of the device as a pivot into the local network. The originating VulDB record states the exploit has been published and may be used, although curated PoC trackers list no confirmed public PoC, the flaw is not on the CISA KEV list, and there is no evidence of in-the-wild exploitation to date.
What to do: Check D-Link's security advisories for a fixed DWR-M921 firmware release and upgrade if one is available (no patched version is identified in this record, and the hardware line is aging). Immediately disable remote/WAN access to the web management interface (which exposes /boafrm/formDiskFormat), restrict management to the LAN or a dedicated firewall rule, and replace any default admin credentials. Monitor the device for unexpected configuration changes or outbound traffic, and consider isolating or retiring end-of-life routers that cannot be patched.
| D-Link DWR-M921 | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.