Description
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-06-05
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A remote attacker can exploit a command injection flaw in the formSmsManage handler of D-Link DWR-M920 routers running firmware 1.1.50 or 1.1.70. Manipulating the action_value argument in the sub_41C8E8 function allows injection of shell commands that are executed on the device. This vulnerability is classified as CWE-74 and CWE-77 and provides the attacker with the ability to execute arbitrary commands, potentially compromising confidentiality, integrity, and availability of the router.

Affected Systems

The affected hardware is the D-Link DWR-M920 wireless router, specifically firmware builds 1.1.50 and 1.1.70. No other products or firmware releases are listed as vulnerable in the official CNA data.

Risk and Exploitability

With a CVSS score of 5.3 the risk is moderate, but the exploit is public and demonstrated in the wild. The attack vector is remote, requiring only an HTTP request to the router’s web interface. The vulnerability is not listed in the CISA KEV catalog; however, because the payload is freely available, an attacker could deploy it without additional tools.

Generated by OpenCVE AI on June 5, 2026 at 04:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the DWR‑M920 firmware to the latest version that contains the command‑injection fix from D‑Link.
  • If a patch is not yet available, disable the web management interface or restrict it to trusted IP addresses using firewall rules or router ACLs.
  • Apply network segmentation to isolate the router from untrusted networks and block inbound HTTP traffic to the /boafrm/formSmsManage endpoint except from authorized sources.
  • Implement a web application firewall or intrusion detection rule that blocks malformed action_value parameters or known command‑injection payloads.

Generated by OpenCVE AI on June 5, 2026 at 04:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
First Time appeared D-link
D-link dwr-m920
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:d-link:dwr-m920:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m920
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-05T00:00:17.909Z

Reserved: 2026-06-04T15:40:34.401Z

Link: CVE-2026-10878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-05T00:16:59.730

Modified: 2026-06-05T00:16:59.730

Link: CVE-2026-10878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T04:30:31Z

Weaknesses