D-Link DWR-M921 command injection via disk format endpoint
D-Link DWR-M921 firmware 1.1.52 passes the partition argument from /boafrm/formDiskFormat to the system shell without sanitization, enabling OS command injection. CVSS 9.1 critical.
- Vendor
- D-Link
- Product
- DWR-M921 (firmware 1.1.52)
- CVSS
- 9.1
- EPSS (exploit probability)
- 2.8%
- Status
- unpatched
- Published
D-Link DWR-M921 firmware version 1.1.52 contains an OS command injection vulnerability in the system function handling /boafrm/formDiskFormat. The partition parameter reaches the system shell unsanitized, allowing an attacker to execute arbitrary OS commands through the router’s BOA web server.
No official D-Link advisory or firmware update had been published as of September 16, 2026. Restricting access to the router’s web management interface to trusted hosts reduces exposure while a patch is pending.
See the NVD entry for the full record.
