Impact
The vulnerability arises from an insecure use of the system() function within the /boafrm/formDiskPartition handler of the D-Link DWR‑M921 firmware 1.1.52. By supplying a crafted devicename value, an attacker can inject arbitrary operating‑system commands, allowing execution of commands on the device with the privileges of that process. This capability enables full control of the router, including disrupting network services, exfiltrating data, installing malware, or modifying device configuration. The weakness directly reflects insecure input handling that permits command injection.
Affected Systems
The affected product is the D-Link DWR‑M921 router running firmware version 1.1.52. No other vendors or product lines are listed in the advisory data.
Risk and Exploitability
The CVSS score of 5.1 signals a moderate severity for this vulnerability. With an EPSS score of 2%, the overall likelihood of exploitation is low but non‑negligible. The vulnerability is not present in the CISA KEV catalog, indicating limited confirmed use in the wild. Attackers can reach the vulnerable endpoint via the router’s web interface, but this is inferred from the context of the function handler and the description; the advisory does not explicitly confirm the access vector. Successful exploitation would allow remote command execution without requiring additional compromise steps.
OpenCVE Enrichment