Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-90699

D-Link DWR-M920 command injection via SIM PIN management endpoint

D-Link DWR-M920 firmware 1.1.7 passes the newPin argument from /boafrm/formPinManageSetup directly to the system shell, allowing OS command injection. CVSS 9.9 critical.

cat cve-2026-90699.json
Vendor
D-Link
Product
DWR-M920 (firmware 1.1.7)
CVSS
9.9
EPSS (exploit probability)
1.6%
Status
unpatched
Published

D-Link DWR-M920 firmware version 1.1.7 contains an OS command injection vulnerability in the function sub_41E60C, which handles the /boafrm/formPinManageSetup endpoint in the BOA embedded web server. The newPin parameter is passed to a system call without sanitization, giving an attacker the ability to execute arbitrary commands on the underlying OS.

No official D-Link advisory or firmware update had been published as of September 16, 2026. Restricting access to the router’s web management interface to trusted hosts is the practical mitigation while a patch is pending.

See the NVD entry for the full record.