Junglewise Threat Intelligence

CVE-2026-11341: D-Link DWR-M920 OS command injection in formIMEISetup

CVE-2026-11341 · Severity: medium · CVSS 6.3 · Published 2026-06-05

Technologies: D-Link DWR-M920. Vendors: D-Link.

Executive brief

A security vulnerability has been identified in the D-Link DWR-M920 4G LTE router. This flaw allows a remote attacker with basic user access to execute unauthorized system commands on the device. Successful exploitation could lead to full device takeover, disruption of internet services, or unauthorized access to the local network.

Technical details

An OS command injection vulnerability exists in the D-Link DWR-M920 router up to version 1.1.50. The flaw is located within the sub_412DA0 function of the /boafrm/formIMEISetup component. The vulnerability stems from improper neutralization of the IMEI_value argument, which allows an attacker to inject and execute arbitrary shell commands. While the attack can be initiated remotely over the network, it requires low-level authentication (PR:L). Public exploit code has been disclosed, increasing the risk of exploitation.

Affected products

  • D-Link DWR-M920 up to 1.1.50

Timeline

  • 2026-06-05: disclosed: Vulnerability published by VulDB/NVD

References

Related threats