Junglewise Threat Intelligence

CVE-2026-10878: D-Link DWR-M920 command injection in formSmsManage

CVE-2026-10878 · Severity: medium · CVSS 6.3 · Published 2026-06-05

Technologies: D-Link DWR-M920. Vendors: D-Link.

Executive brief

A security vulnerability exists in the D-Link DWR-M920 4G LTE router, a device used to provide internet connectivity for homes and small offices. An attacker can exploit this flaw to take control of the device by injecting malicious commands through the SMS management interface. This could lead to unauthorized access to the network, interception of data, or disruption of internet services.

Technical details

A command injection and stack-based buffer overflow vulnerability exists in the D-Link DWR-M920 router versions 1.1.50 and 1.1.70. The flaw is located in the sub_41C8E8 function within the /boafrm/formSmsManage component. The application fails to perform length checks or sanitization on the 'action_value' parameter before passing it to the 'sprintf' function (causing a buffer overflow) and subsequently to the 'system' function. A remote attacker with low privileges can exploit this to execute arbitrary shell commands on the underlying operating system. Public exploit code is reportedly available.

Affected products

  • D-Link DWR-M920 1.1.50, 1.1.70

Timeline

  • 2026-06-05: advisory: NVD publication date
  • 2026-06-04: disclosed: Initial disclosure by VulDB

References

Related threats