Description
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-09-14
Score: 9.4 Critical
EPSS: 3.6% Low
KEV: No
Impact: Remote OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

A flaw in the formDiskCreateShare routine of the D‑Link DWR‑M921 router allows a remote attacker to supply a crafted folderpath value that is directly embedded into a system specify authentication requirements; it is inferred that the attacker can be unauthenticated. This results in arbitrary operating‑system command execution, giving the attacker full control over the device. The vulnerability is a classic weaknesses where unsanitized input leads to command injection. As a result, confidentiality, integrity, and availability of the network can be compromised, potentially leading to a full network takeover.

Affected Systems

The affected product is the D‑Link DWR‑M921 model running firmware version 1.1.52. Newer firmware releases from D‑Link that do not include the vulnerable formDiskCreateShare implementation are expected to mitigate the flaw. website for an updated firmware image. Until a patch is available, devices running the specified firmware are at risk.

Risk and Exploitability

The CVSS base score of 9.4 classSS score of 3% indicates a moderate exploitation probability, but the public disclosure and known exploitation on the open web suggest that the risk remains high. The CVE description does not specify authentication or local privilege requirements; it is inferred that the attack may be launched remotely without authentication and does not require local privileges. The absence of a KEV listing does not negate the potential for abuse; the remote command execution remains a top priority for defenders.

Generated by OpenCVE AI on September 21, 2026 at 00:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update from D-Link that removes the formDiskCreateShare vulnerability.
  • Disable remote web‑management on the router or restrict it to trusted IP ranges until a patch can be applied.
  • Configure network perimeter devices to block or limit inbound traffic to the router’s management ports (e.g., HTTP/HTTPS) from external networks.

Generated by OpenCVE AI on September 21, 2026 at 00:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Title D-Link DWR-M921 formDiskCreateShare system os command injection
First Time appeared D-link
D-link dwr-m921
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dwr-m921:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m921
References
Metrics cvssV2_0

{'score': 8.3, 'vector': 'AV:N/AC:L/Au:M/C:C/I:C/A:C/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 9.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:26:09.777Z

Reserved: 2026-09-13T07:57:25.660Z

Link: CVE-2026-90703

cve-icon Vulnrichment

Updated: 2026-09-15T17:26:06.806Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T10:17:05.610

Modified: 2026-09-15T18:19:38.113

Link: CVE-2026-90703

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')