CVE-2026-90704: D-Link DWR-M921 formDiskPartition system command injection
Published Sep 14, 2026
·Updated
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
1 affected component
D-Link DWR-M921=1.1.52
Event History
Sep 14, 2026
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The supplied vector indicates network access is required and privileges are required (PR:H). No user interaction is required.
2
Is public exploit information available?
Yes. The vulnerability description states that an exploit has been made public and could be used.
3
Which device version is identified as affected?
The reported affected version is D-Link DWR-M921 1.1.52.