GHSA-qrw7-pm2g-vw5pLowCVSS 6.6
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
🔗 References (8)
- https://nvd.nist.gov/vuln/detail/CVE-2026-90704
- https://gist.github.com/H3rmesk1t/2052767b9fb397e311c17383a0e19021
- https://vuldb.com/cve/CVE-2026-90704
- https://vuldb.com/submit/917696
- https://vuldb.com/vuln/403246
- https://vuldb.com/vuln/403246/cti
- https://www.dlink.com
- https://github.com/advisories/GHSA-qrw7-pm2g-vw5p