Impact
The vulnerability is an OS command injection flaw located in the /boafrm/formDiskFormat interface of the D-Link DWR‑M921. By supplying a specially crafted value for the partition argument, an attacker that can reach the device remotely may execute arbitrary shell commands on the underlying operating system. This flaw is listed as CWE‑77 and CWE‑78 and allows remote code execution, potentially compromising the confidentiality, integrity, and availability of the device and any connected networks.
Affected Systems
The affected product is the D-Link DWR‑M921 consumer router running firmware version 1.1.52. No other versions or products are indicated as vulnerable in the available data.
Risk and Exploitability
The CVSS score of 9.4 indicates a critical severity. The EPSS score is 3%, and the exploit has been published and may be used, implying that attackers can launch attacks without significant barriers. The vulnerability is not yet listed in the CISA KEV catalog, so it may not be widely tracked by official advisories, increasing the risk that organizations may not be aware of the issue. Based on the description, it is inferred that the attacker requires remote access to the device’s web interface to trigger the flaw, so disabling remote management or restricting it to trusted networks reduces the attack surface.
OpenCVE Enrichment