Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 30 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dwr-m920 Dlink dwr-m920 Firmware |
|
| CPEs | cpe:2.3:h:dlink:dwr-m920:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dwr-m920_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dwr-m920 Dlink dwr-m920 Firmware |
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dwr-m920 |
|
| Vendors & Products |
D-link
D-link dwr-m920 |
Mon, 29 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Dec 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the file /boafrm/formLtefotaUpgradeFibocom. This manipulation of the argument fota_url causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited. | |
| Title | D-Link DWR-M920 formLtefotaUpgradeFibocom sub_4155B4 command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-29T14:26:08.160Z
Reserved: 2025-12-28T09:10:09.118Z
Link: CVE-2025-15191
Updated: 2025-12-29T14:26:05.093Z
Status : Analyzed
Published: 2025-12-29T14:15:56.427
Modified: 2025-12-30T20:41:41.547
Link: CVE-2025-15191
No data.
OpenCVE Enrichment
Updated: 2025-12-29T23:03:49Z