Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
8.5
CVE-2026-90703: D-Link DWR-M921 allows remote command execution
CVE-2026-90703 · published 26 days ago
Summary
The D-Link DWR-M921 router (firmware 1.1.52) lets an attacker send a specially crafted request to the /boafrm/formDiskCreateShare page and run operating‑system commands on the device. This can be done from anywhere on the network, potentially giving the attacker control of the router. Apply the latest firmware update from D‑Link and limit external access to the router’s management interface.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| d-link | dwr-m921 | 1.1.52 |
Original advisory text
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to ...
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Severity
8.5
High
Type
CWE-78OS Command Injection
CWE-77Command Injection
Timeline
Published14 Sep 2026
Updated3 Oct 2026
First seen14 Sep 2026
Track software like this
Free during beta