Executive brief
D-Link DWR-M921 is a wireless router used to provide internet connectivity in homes and small offices. A critical vulnerability in its web management interface allows authenticated users to execute arbitrary system commands with root privileges by manipulating the folder path parameter in the share creation feature. An attacker with valid router credentials could take complete control of the device, intercept network traffic, or use it as a foothold for attacking connected networks.
Technical details
The vulnerability is an OS command injection (CWE-78) in the /boafrm/formDiskCreateShare handler within the boa web server binary. The folderpath parameter is unsafely concatenated into a mkdir shell command executed via system() without proper sanitization: sprintf(v26, "mkdir %s/\"%s\"", folderpath, foldername); system(v26). Since folderpath is placed outside quotes, an attacker can inject arbitrary commands using semicolon separators (e.g., /mnt/usb;malicious_command;). The vulnerability requires valid web UI authentication (webuicookie session) but executes with root privileges. The foldername parameter (inside quotes) is also exploitable via command substitution syntax $(CMD). Patches should implement strict input validation using whitelists or replace system() calls with safe API equivalents like mkdir().
Affected products
- D-Link DWR-M921 1.1.52
Timeline
- 2026-08-06: disclosed: Vulnerability details published on GitHub
- 2026-09-14: advisory: NVD advisory published