CVE-2026-90705: D-Link DWR-M921 Boa Dispatch Table formsysCmd os command injection
A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be executed remotely, but the supplied CVSS vector indicates high privileges are required. No user interaction is required.
What access or endpoint is involved?
The affected functionality is the formsysCmd handler at /boafrm/formsysCmd in the Boa Dispatch Table. Exploitation involves manipulating the sysCmd argument to inject operating-system commands.
Is exploitation theoretical?
No. A public exploit disclosure exists and may be used, although the provided vector rates exploit code maturity as proof-of-concept and report confidence as reasonable.
Which version is identified as affected?
The provided information identifies D-Link DWR-M921 version 1.1.52 as affected. It does not establish whether other versions are affected or fixed.