CVE-2026-90704

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

  • Published Sep 14, 2026
  • CVSS 2.0 low
  • 2.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90704 at the National Vulnerability Database