Command Injection Vulnerability in D-Link DWR-M920 Router
CVE-2026-11339
Key Information:
Badges
What is CVE-2026-11339?
A command injection vulnerability exists in the D-Link DWR-M920 router, specifically in the function sub_41CF20 located within the /boafrm/formUSSDSetup file. Exploiting this vulnerability allows an attacker to manipulate the ussdValue argument remotely, potentially executing arbitrary commands on the device. This exposure enables malicious entities to perform unauthorized actions on affected systems, highlighting the need for immediate attention and patching.
Affected Version(s)
DWR-M920 1.1.0
DWR-M920 1.1.1
DWR-M920 1.1.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved