Description
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-09-14
Score: 9.4 Critical
EPSS: 3.3% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection in the D-Link DWR‑M920 firmware 1.1.7. The sub_41E60C function inside /boafrm/formPinManageSetup accepts a newPin parameter that is passed to the operating system without proper validation. An attacker can supply crafted input to execute arbitrary commands, leading to full remote code execution on the device. This flaw aligns with CWE-77 and CWE-78 and permits compromise of confidentiality, integrity, and availability.

Affected Systems

D-Link DWR‑M920 routers running firmware version 1.1.7 are affected. The issue originates from the formPinManageSetup page, which is typically reachable through the router’s web interface. No other firmware releases are currently documented as vulnerable.

Risk and Exploitability

The advisory lists a CVSS score of 9.4, indicating critical severity. The EPSS score of 3% indicates a moderate likelihood of exploitation in the wild, and public proof‑of‑concept code is available. The flaw can be triggered remotely over the web interface, so devices exposed to the internet or unmanaged networks are at risk. The vulnerability is not yet in the CISA KEV catalog, but its high severity and public availability warrant urgent attention.

Generated by OpenCVE AI on September 25, 2026 at 00:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from D-Link that contains a fix for sub_41E60C.
  • Disable remote web management on the router or restrict it to trusted networks using a firewall or ACL.
  • As an interim measure, change the administrator password and monitor logs for unusual activity.

Generated by OpenCVE AI on September 25, 2026 at 00:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Title D-Link DWR-M920 formPinManageSetup sub_41E60C os command injection
First Time appeared D-link
D-link dwr-m920
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dwr-m920:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m920
References
Metrics cvssV2_0

{'score': 9, 'vector': 'AV:N/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.9, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T10:16:22.885Z

Reserved: 2026-09-13T05:24:42.918Z

Link: CVE-2026-90699

cve-icon Vulnrichment

Updated: 2026-09-14T10:16:17.012Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T09:17:02.530

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90699

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-25T00:45:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')