CVE-2026-90705
A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
- Published Sep 14, 2026
- CVSS 2.0 low
- 2.3% chance of exploitation in the next 30 days (EPSS)