Impact
A flaw in the Boa Dispatch Table’s forms arbitrary shell commands via the sysCmd parameter. An unauthenticated remote user can send a crafted request that is evaluated directly by the underlying operating system, enabling execution of any command. The vulnerability is categorized as a command injection and OS command injection weakness, which can compromise the entire system’s confidentiality, integrity, and availability if exploited.
Affected Systems
The flaw is found in D‑Link DWR‑M921 network gear running firmware 1.1.52. This affects the Boa Dispatch Table component exposed through the /boafrm/formsysCmd endpoint. Devices identified as D‑Link DWR‑M921 routers with the noted firmware version are at risk.
Risk and Exploitability
The assessed CVSS score is 5.1, indicating a medium severity level. The EPSS score is 2%, indicating a modest probability of exploitation by attackers. The vulnerability is not listed in the CISA KEV catalog, therefore no targeted alert is currently available. Since remote exploitation is possible without local access, the risk is elevated for systems that expose the affected interface to the internet.
OpenCVE Enrichment