CVE-2026-90703
moderateAuthenticated OS Command Injection in D-Link DWR-M921 LTE Router
D-Link DWR-M921 routers running firmware 1.1.52 contain an OS command injection flaw in the system function behind the /boafrm/formDiskCreateShare web endpoint, which handles creation of USB disk shares. An attacker submits a crafted folderpath argument — the shared-folder path field — that is passed unsanitized into an operating-system command, resulting in arbitrary command execution on the router with high impact to confidentiality, integrity, and availability. The CVSS 4.0 score of 8.5 (AV:N/AC:L/PR:H) indicates the flaw is remotely exploitable but requires high privileges, consistent with an attacker holding an authenticated administrator session on the router's web interface. Any DWR-M921 unit on firmware 1.1.52 reachable over the network is affected; the source report states the exploit has been publicly disclosed, though the issue is not on the CISA KEV list and no confirmed in-the-wild attacks are tracked.
What to do: Check D-Link's official security advisories for a firmware release newer than 1.1.52 and upgrade as soon as one is available; if the model is end-of-support with no patch planned, replace the device. Disable remote (WAN) access to the router's web administration interface, keep management restricted to the trusted LAN, and turn off the USB disk-sharing feature if it is not needed. Review router configuration and logs for unexpected shared folders or altered settings that could indicate prior abuse of this endpoint.
| D-Link DWR-M921 | 1.1.52 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
- Weakness
- CWE-77, CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.