Description
A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Published: 2026-09-14
Score: 5.1 Medium
EPSS: 2.3% Low
KEV: No
Impact: Remote Command Execution
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the formWsc function of the D-Link DWR‑M921 firmware 1.1.52. Manipulation of the targetAPSsid parameter allows an attacker to inject operating‑system commands, resulting in arbitrary command execution. This flaw is an instance of CWE‑77 (OS Command Injection) and CWE‑78 (Untrusted Input to OS Command). The impact is that a remote actor can run arbitrary commands on the device, compromising confidentiality, integrity, and availability of the network and connected services.

Affected Systems

D‑Link DWR‑M921 routers running firmware version 1.1.52. No other versions are listed as affected in the current data.

Risk and Exploitability

The CVSS base score of 5.1 indicates a moderate severity. The EPSS score of 2% indicates a low but non‑zero likelihood of exploitation. Because the flaw is exploitable remotely, the risk profile is elevated; an attacker with network access to the device could achieve full command exec. The CISA KEV catalog does not list this vulnerability, yet the existence of a public exploit suggests it may be actively used.

Generated by OpenCVE AI on September 21, 2026 at 00:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the DWR‑M921 that addresses the command injection flaw.
  • If a firmware update is not immediately available, disable the Web‑based WSC (Wi‑Fi Simple Configuration) feature or block remote access to the /boafrm/formWsc endpoint using firewall rules, thereby preventing external manipulation of targetAPSsid.
  • Enable logging of HTTP requests to the /boafrm/formWsc endpoint and regularly review logs for attempts to inject command characters or suspicious payloads.

Generated by OpenCVE AI on September 21, 2026 at 00:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Title D-Link DWR-M921 formWsc os command injection
First Time appeared D-link
D-link dwr-m921
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:h:d-link:dwr-m921:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m921
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.6, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T14:33:15.845Z

Reserved: 2026-09-13T07:57:55.599Z

Link: CVE-2026-90706

cve-icon Vulnrichment

Updated: 2026-09-14T14:33:03.455Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T11:17:06.930

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90706

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T00:45:08Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')