Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-90703

D-Link DWR-M921 command injection via disk share creation endpoint

D-Link DWR-M921 firmware 1.1.52 passes the folderpath argument from /boafrm/formDiskCreateShare to the system shell without sanitization, enabling OS command injection. CVSS 9.1 critical.

cat cve-2026-90703.json
Vendor
D-Link
Product
DWR-M921 (firmware 1.1.52)
CVSS
9.1
EPSS (exploit probability)
2.8%
Status
unpatched
Published

D-Link DWR-M921 firmware version 1.1.52 contains an OS command injection vulnerability in the system function handling /boafrm/formDiskCreateShare. The folderpath parameter passes to the system shell without sanitization, giving an attacker the ability to execute arbitrary OS commands via the BOA embedded web server.

No official D-Link advisory or firmware update had been published as of September 16, 2026. Restricting access to the router’s web management interface to trusted hosts reduces exposure while a patch is pending.

See the NVD entry for the full record.