CVE-2026-90702

Summary

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.

Affected Software

VendorProductVersion RangeStatus
D-LinkDWR-M9211.1.52affected

Weaknesses

  • CWE-78: OS Command Injection
  • CWE-77: Command Injection

References