Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 30 Dec 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dlink
Dlink dwr-m920 Dlink dwr-m920 Firmware |
|
| CPEs | cpe:2.3:h:dlink:dwr-m920:-:*:*:*:*:*:*:* cpe:2.3:o:dlink:dwr-m920_firmware:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dlink
Dlink dwr-m920 Dlink dwr-m920 Firmware |
Mon, 29 Dec 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
D-link
D-link dwr-m920 |
|
| Vendors & Products |
D-link
D-link dwr-m920 |
Mon, 29 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 29 Dec 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Title | D-Link DWR-M920 formLtefotaUpgradeQuectel sub_415328 command injection | |
| Weaknesses | CWE-74 CWE-77 |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2025-12-29T16:11:38.000Z
Reserved: 2025-12-28T09:10:12.267Z
Link: CVE-2025-15192
Updated: 2025-12-29T16:11:32.392Z
Status : Analyzed
Published: 2025-12-29T15:16:00.377
Modified: 2025-12-30T20:41:49.483
Link: CVE-2025-15192
No data.
OpenCVE Enrichment
Updated: 2025-12-29T23:03:44Z