CVE-2026-90702: D-Link DWR-M921 formDiskFormat system os command injection
Published Sep 14, 2026
·Updated
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
1 affected component
D-Link DWR-M921=1.1.52
Event History
Sep 14, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The vulnerable endpoint can be attacked remotely, but the provided severity vector indicates that high privileges are required. No user interaction is required.
2
Is public exploit code available?
Yes. An exploit has been published and may be used.
3
Which product version is identified as affected?
The reported affected version is D-Link DWR-M921 1.1.52.