Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.5

CVE-2026-90702: D-Link DWR-M921 router allows remote command execution

CVE-2026-90702 · published 26 days ago
Summary

The router’s formDiskFormat feature can be tricked into running arbitrary commands when a specially crafted request is sent, letting an attacker control the device from anywhere on the network. This risk can be removed by installing the latest firmware or applying the vendor’s security update.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
d-link dwr-m921 1.1.52
Original advisory text
D-Link DWR-M921 formDiskFormat system os command injection
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
8.5 High
Exploitation
4% chance of attack within 30 days
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published14 Sep 2026
Updated3 Oct 2026
First seen14 Sep 2026
Sources
CVE-2026-90702 · MITRE
Track software like this
Free during beta