Impact
The vulnerability is an OS command injection in the D-Link DWR‑M920 firmware 1.1.7. The sub_41E60C function inside /boafrm/formPinManageSetup accepts a newPin parameter that is passed to the operating system without proper validation. An attacker can supply crafted input to execute arbitrary commands, leading to full remote code execution on the device. This flaw aligns with CWE-77 and CWE-78 and permits compromise of confidentiality, integrity, and availability.
Affected Systems
D-Link DWR‑M920 routers running firmware version 1.1.7 are affected. The issue originates from the formPinManageSetup page, which is typically reachable through the router’s web interface. No other firmware releases are currently documented as vulnerable.
Risk and Exploitability
The advisory lists a CVSS score of 9.4, indicating critical severity. The EPSS score of 3% indicates a moderate likelihood of exploitation in the wild, and public proof‑of‑concept code is available. The flaw can be triggered remotely over the web interface, so devices exposed to the internet or unmanaged networks are at risk. The vulnerability is not yet in the CISA KEV catalog, but its high severity and public availability warrant urgent attention.
OpenCVE Enrichment