Impact
The vulnerability resides in the formWsc function of the D-Link DWR‑M921 firmware 1.1.52. Manipulation of the targetAPSsid parameter allows an attacker to inject operating‑system commands, resulting in arbitrary command execution. This flaw is an instance of CWE‑77 (OS Command Injection) and CWE‑78 (Untrusted Input to OS Command). The impact is that a remote actor can run arbitrary commands on the device, compromising confidentiality, integrity, and availability of the network and connected services.
Affected Systems
D‑Link DWR‑M921 routers running firmware version 1.1.52. No other versions are listed as affected in the current data.
Risk and Exploitability
The CVSS base score of 5.1 indicates a moderate severity. The EPSS score of 2% indicates a low but non‑zero likelihood of exploitation. Because the flaw is exploitable remotely, the risk profile is elevated; an attacker with network access to the device could achieve full command exec. The CISA KEV catalog does not list this vulnerability, yet the existence of a public exploit suggests it may be actively used.
OpenCVE Enrichment