Junglewise Threat Intelligence

CVE-2026-90706: D-Link DWR-M921 OS command injection in formWsc

CVE-2026-90706 · Severity: medium · CVSS 6.6 · Published 2026-09-14

Technologies: D-Link DWR-M921. Vendors: D-Link.

Executive brief

The D-Link DWR-M921 wireless router contains a command injection vulnerability in its web management interface. An authenticated attacker can inject arbitrary shell commands through an improperly sanitized parameter, allowing them to execute commands with root privileges on the device. This could lead to complete compromise of the router, exposing or intercepting all network traffic passing through it.

Technical details

The vulnerability is an OS command injection (CWE-78) in the formWsc handler at address 0x45A5A0 within /bin/boa. The targetAPSsid parameter is filtered by sub_43B224, which only escapes backslash, double-quote, and backtick characters, leaving shell metacharacters ($, parentheses, semicolon) unfiltered. An attacker with a valid session cookie can inject commands using $(...) command substitution syntax within the double-quoted iwpriv command. The attack requires authentication via webuicookie but is otherwise remotely exploitable. Proof-of-concept code is publicly available on GitHub; patches or firmware updates have not been confirmed.

Affected products

  • D-Link DWR-M921 1.1.52

Timeline

  • 2026-08-06: disclosed: Vulnerability disclosed on GitHub gist
  • 2026-09-14: advisory: CVE-2026-90706 published on NVD
  • 2026-09-14: other: Public exploit code available

References

Related threats