Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
CVE · Critical CVE-2026-90702 2026-09-14

CVE-2026-90702: D-Link DWR-M921 Command Injection with Public Exploit

"A published proof-of-concept exploit targets an OS command injection flaw in D-Link DWR-M921 routers running firmware 1.1.52, scored CVSS 9.1 (Critical)."

A published proof-of-concept exploit targets an OS command injection flaw in D-Link DWR-M921 routers running firmware 1.1.52, scored CVSS 9.1 (Critical).

What Is It

CVE-2026-90702 is an OS command injection vulnerability (CWE-77, CWE-78) in D-Link DWR-M921 version 1.1.52. The flaw sits in the system function of the file /boafrm/formDiskFormat. Manipulating the partition argument causes the device to execute attacker-supplied operating system commands. The attack can be initiated remotely, and per the NVD record, the exploit has been published and may be used.

Why It Matters

The CVSS 3.1 base score is 9.1 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, network attack vector, low attack complexity, no user interaction, and a changed scope with complete compromise of confidentiality, integrity, and availability. The changed scope reflects that command execution on the router can reach beyond the vulnerable component itself. Privileges required are rated HIGH, which is the one meaningful constraint: an attacker needs elevated access before triggering the injection. The separate CVSS 4.0 assessment (base 8.5, HIGH) rates exploit maturity as PROOF_OF_CONCEPT, consistent with the published exploit code referenced in the CVE record.

Exploit maturity of PROOF_OF_CONCEPT means working code is public but the referenced sources stop short of documenting confirmed in-the-wild attacks. Public exploit availability alone still warrants prompt attention on internet-reachable devices.

What's Vulnerable

No other products or versions are identified in the supplied source material.

Patch Status

The supplied NVD record lists no patch, fixed version, or vendor advisory. The CVE was published 2026-09-14 with vulnerability status "Received," meaning NVD analysis is still pending. The only vendor-related reference is D-Link's main website. Operators should check directly with D-Link for firmware availability and restrict administrative access to affected devices in the meantime.

Sources