Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.6
CVE-2026-90699: D-Link DWR-M920 allows remote command execution via PIN page
CVE-2026-90699 · published 26 days ago
Summary
The DWR-M920 router version 1.1.7 lets an attacker send specially crafted data to the PIN management page, which can cause the device to run any command the attacker chooses. This can be done from anywhere on the internet and could let someone take control of the router. Apply the latest firmware update from D‑Link or restrict internet access to the router’s management interface until it is patched.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dwr-m920 | 1.1.7 |
Original advisory text
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os comman...
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.6
High
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published14 Sep 2026
Updated4 Oct 2026
First seen14 Sep 2026
Track software like this
Free during beta