Description
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-06-05
Score: 5.3 Medium
EPSS: 4.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote attacker can exploit a command injection flaw in the formSmsManage handler of D-Link DWR-M920 routers running firmware 1.1.50 or 1.1.70. Manipulating the action_value argument in the sub_41C8E8 function allows injection of shell commands that are executed on the device. This vulnerability is classified as CWE-74 and CWE-77 and provides the attacker with the ability to execute arbitrary commands, potentially compromising confidentiality, integrity, and availability of the router.

Affected Systems

The affected hardware is the D-Link DWR-M920 wireless router, specifically firmware builds 1.1.50 and 1.1.70. No other products or firmware releases are listed as vulnerable in the official CNA data.

Risk and Exploitability

With a CVSS score of 5.3 the risk remains moderate, and the EPSS score of 4% indicates a moderate likelihood of exploitation, but the exploit is public and demonstrated in the wild. The attack vector is remote, requiring only an HTTP request to the router, not listed in the CISA KEV catalog; however, because the payload is freely available, an attacker could deploy it without additional tools.

Generated by OpenCVE AI on June 18, 2026 at 03:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DWR‑M920 firmware to the latest version that contains the command‑injection fix from D‑Link.
  • If a patch is not yet available, disable the web management interface or restrict it to trusted IP addresses using firewall rules or router ACLs.
  • Apply network segmentation to isolate the router from untrusted networks and block inbound HTTP traffic to the /boafrm/formSmsManage endpoint except from authorized sources.
  • Implement a web application firewall or intrusion detection rule that blocks malformed action_value parameters or known command‑injection payloads.

Generated by OpenCVE AI on June 18, 2026 at 03:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dwr-m920
Dlink dwr-m920 Firmware
CPEs cpe:2.3:h:dlink:dwr-m920:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m920_firmware:1.1.50:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m920_firmware:1.1.70:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dwr-m920
Dlink dwr-m920 Firmware

Fri, 05 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
First Time appeared D-link
D-link dwr-m920
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:d-link:dwr-m920:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m920
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Dwr-m920
Dlink Dwr-m920 Dwr-m920 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-05T19:28:05.511Z

Reserved: 2026-06-04T15:40:34.401Z

Link: CVE-2026-10878

cve-icon Vulnrichment

Updated: 2026-06-05T19:27:59.067Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-05T00:16:59.730

Modified: 2026-06-05T16:48:39.577

Link: CVE-2026-10878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T04:00:15Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')