CVE-2026-90703

A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Scoring

Severity
CRITICAL
CVSS base score
9.4
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
EPSS probability
2.80%
CWE
CWE-78, CWE-77
Published
2026-09-14
Last modified
2026-09-15

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs