Description
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Published: 2026-09-14
Score: 9.4 Critical
EPSS: 3.6% Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS command injection flaw located in the /boafrm/formDiskFormat interface of the D-Link DWR‑M921. By supplying a specially crafted value for the partition argument, an attacker that can reach the device remotely may execute arbitrary shell commands on the underlying operating system. This flaw is listed as CWE‑77 and CWE‑78 and allows remote code execution, potentially compromising the confidentiality, integrity, and availability of the device and any connected networks.

Affected Systems

The affected product is the D-Link DWR‑M921 consumer router running firmware version 1.1.52. No other versions or products are indicated as vulnerable in the available data.

Risk and Exploitability

The CVSS score of 9.4 indicates a critical severity. The EPSS score is 3%, and the exploit has been published and may be used, implying that attackers can launch attacks without significant barriers. The vulnerability is not yet listed in the CISA KEV catalog, so it may not be widely tracked by official advisories, increasing the risk that organizations may not be aware of the issue. Based on the description, it is inferred that the attacker requires remote access to the device’s web interface to trigger the flaw, so disabling remote management or restricting it to trusted networks reduces the attack surface.

Generated by OpenCVE AI on September 21, 2026 at 00:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the firmware to a version that contains the fix for the /boafrm/formDiskFormat injection flaw.
  • Block or restrict external access to the router’s management interface using a firewall or access control list.
  • Configure the device to allow remote management only from trusted IP addresses or subnets.

Generated by OpenCVE AI on September 21, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 09:45:00 +0000

Type Values Removed Values Added
Description A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Title D-Link DWR-M921 formDiskFormat system os command injection
First Time appeared D-link
D-link dwr-m921
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dwr-m921:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m921
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:57:36.036Z

Reserved: 2026-09-13T07:57:22.303Z

Link: CVE-2026-90702

cve-icon Vulnrichment

Updated: 2026-09-15T13:49:12.404Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T10:17:05.447

Modified: 2026-09-15T14:17:31.210

Link: CVE-2026-90702

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')