Description
A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: 2.3% Low
KEV: No
Impact: Remote OS Command Injection
Action: Patch Now
AI Analysis

Impact

A flaw in the Boa Dispatch Table’s forms arbitrary shell commands via the sysCmd parameter. An unauthenticated remote user can send a crafted request that is evaluated directly by the underlying operating system, enabling execution of any command. The vulnerability is categorized as a command injection and OS command injection weakness, which can compromise the entire system’s confidentiality, integrity, and availability if exploited.

Affected Systems

The flaw is found in D‑Link DWR‑M921 network gear running firmware 1.1.52. This affects the Boa Dispatch Table component exposed through the /boafrm/formsysCmd endpoint. Devices identified as D‑Link DWR‑M921 routers with the noted firmware version are at risk.

Risk and Exploitability

The assessed CVSS score is 5.1, indicating a medium severity level. The EPSS score is 2%, indicating a modest probability of exploitation by attackers. The vulnerability is not listed in the CISA KEV catalog, therefore no targeted alert is currently available. Since remote exploitation is possible without local access, the risk is elevated for systems that expose the affected interface to the internet.

Generated by OpenCVE AI on September 21, 2026 at 00:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest firmware revision that removes the command injection flaw.
  • Disable or restrict remote access to the it to trusted internal networks only.
  • Implement network segmentation and firewall rules to block unsolicited traffic to the administrative interface.
  • Monitor device logs for anomalous sysCmd activity as an early detection measure.

Generated by OpenCVE AI on September 21, 2026 at 00:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Title D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection
First Time appeared D-link
D-link dwr-m921
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dwr-m921:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m921
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:51:40.742Z

Reserved: 2026-09-13T07:57:51.782Z

Link: CVE-2026-90705

cve-icon Vulnrichment

Updated: 2026-09-16T14:51:37.266Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:06.740

Modified: 2026-09-16T15:18:40.683

Link: CVE-2026-90705

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T01:00:08Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')