Description
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: 2.3% Low
KEV: No
Impact: Remote Command Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from an insecure use of the system() function within the /boafrm/formDiskPartition handler of the D-Link DWR‑M921 firmware 1.1.52. By supplying a crafted devicename value, an attacker can inject arbitrary operating‑system commands, allowing execution of commands on the device with the privileges of that process. This capability enables full control of the router, including disrupting network services, exfiltrating data, installing malware, or modifying device configuration. The weakness directly reflects insecure input handling that permits command injection.

Affected Systems

The affected product is the D-Link DWR‑M921 router running firmware version 1.1.52. No other vendors or product lines are listed in the advisory data.

Risk and Exploitability

The CVSS score of 5.1 signals a moderate severity for this vulnerability. With an EPSS score of 2%, the overall likelihood of exploitation is low but non‑negligible. The vulnerability is not present in the CISA KEV catalog, indicating limited confirmed use in the wild. Attackers can reach the vulnerable endpoint via the router’s web interface, but this is inferred from the context of the function handler and the description; the advisory does not explicitly confirm the access vector. Successful exploitation would allow remote command execution without requiring additional compromise steps.

Generated by OpenCVE AI on September 21, 2026 at 02:09 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update that addresses the command injection flaw in the DWR‑M921 router.
  • Restrict external access to the router’s management interface by configuring firewall rules or VPN access so that only trusted administrators can reach the web interface.
  • If no update is available immediately, block or disable the /boafrm/formDiskPartition API endpoint through the router’s configuration or web server controls to mitigate the risk of command injection.

Generated by OpenCVE AI on September 21, 2026 at 02:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Title D-Link DWR-M921 formDiskPartition system command injection
First Time appeared D-link
D-link dwr-m921
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:d-link:dwr-m921:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m921
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T11:57:27.713Z

Reserved: 2026-09-13T07:57:36.620Z

Link: CVE-2026-90704

cve-icon Vulnrichment

Updated: 2026-09-14T11:57:23.619Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T10:17:05.767

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90704

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T02:15:08Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')