OS Command Injection Vulnerability in D-Link DWR-M920 Router
CVE-2026-90699
Key Information:
Badges
What is CVE-2026-90699?
A vulnerability has been identified in the D-Link DWR-M920 router version 1.1.7, specifically in the function sub_41E60C located in the file /boafrm/formPinManageSetup. This security flaw allows for the manipulation of the 'newPin' argument, leading to potential OS command injection. Exploitation of this vulnerability can be executed remotely, posing a significant risk. The exploit details have been publicly disseminated, highlighting the urgency for users to secure their devices against potential attacks.
Affected Version(s)
DWR-M920 1.1.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved