CVE-2026-90705

A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

  • Published Sep 14, 2026
  • CVSS 2.0 low
  • 2.3% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-90705 at the National Vulnerability Database