Impact
A flaw in the formDiskCreateShare routine of the D‑Link DWR‑M921 router allows a remote attacker to supply a crafted folderpath value that is directly embedded into a system specify authentication requirements; it is inferred that the attacker can be unauthenticated. This results in arbitrary operating‑system command execution, giving the attacker full control over the device. The vulnerability is a classic weaknesses where unsanitized input leads to command injection. As a result, confidentiality, integrity, and availability of the network can be compromised, potentially leading to a full network takeover.
Affected Systems
The affected product is the D‑Link DWR‑M921 model running firmware version 1.1.52. Newer firmware releases from D‑Link that do not include the vulnerable formDiskCreateShare implementation are expected to mitigate the flaw. website for an updated firmware image. Until a patch is available, devices running the specified firmware are at risk.
Risk and Exploitability
The CVSS base score of 9.4 classSS score of 3% indicates a moderate exploitation probability, but the public disclosure and known exploitation on the open web suggest that the risk remains high. The CVE description does not specify authentication or local privilege requirements; it is inferred that the attack may be launched remotely without authentication and does not require local privileges. The absence of a KEV listing does not negate the potential for abuse; the remote command execution remains a top priority for defenders.
OpenCVE Enrichment