Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.5
CVE-2026-90702: D-Link DWR-M921 router allows remote command execution
CVE-2026-90702 · published 26 days ago
Summary
The router’s formDiskFormat feature can be tricked into running arbitrary commands when a specially crafted request is sent, letting an attacker control the device from anywhere on the network. This risk can be removed by installing the latest firmware or applying the vendor’s security update.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dwr-m921 | 1.1.52 |
Original advisory text
D-Link DWR-M921 formDiskFormat system os command injection
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.5
High
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published14 Sep 2026
Updated3 Oct 2026
First seen14 Sep 2026
Track software like this
Free during beta