CVE-2026-90703: D-Link DWR-M921 formDiskCreateShare system os command injection
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attack can be launched remotely, but the supplied CVSS vector indicates high privileges are required. No user interaction is required.
Which systems are known to be affected?
The affected product and version identified in the available data are D-Link DWR-M921 1.1.52. The vulnerable input is the folderpath argument handled by /boafrm/formDiskCreateShare.
How serious is successful exploitation?
Successful exploitation can result in OS command injection with high impact to confidentiality, integrity, and availability. The CVSS vector also indicates scope can change.
Is exploit code or public exploitation information available?
Yes. The exploit has been publicly disclosed and may be used.