Impact
A remote attacker can exploit a command injection flaw in the formSmsManage handler of D-Link DWR-M920 routers running firmware 1.1.50 or 1.1.70. Manipulating the action_value argument in the sub_41C8E8 function allows injection of shell commands that are executed on the device. This vulnerability is classified as CWE-74 and CWE-77 and provides the attacker with the ability to execute arbitrary commands, potentially compromising confidentiality, integrity, and availability of the router.
Affected Systems
The affected hardware is the D-Link DWR-M920 wireless router, specifically firmware builds 1.1.50 and 1.1.70. No other products or firmware releases are listed as vulnerable in the official CNA data.
Risk and Exploitability
With a CVSS score of 5.3 the risk is moderate, but the exploit is public and demonstrated in the wild. The attack vector is remote, requiring only an HTTP request to the router’s web interface. The vulnerability is not listed in the CISA KEV catalog; however, because the payload is freely available, an attacker could deploy it without additional tools.
OpenCVE Enrichment