PT-2026-47006 · D Link · Dwr-M920
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
D-Link DWR-M920 versions prior to 1.1.51
Description
A flaw in the
sub 412DA0() function within the /boafrm/formIMEISetup file allows for remote OS command injection. This occurs through the manipulation of the IMEI value argument.Recommendations
Update to a version later than 1.1.50.
As a temporary workaround, restrict access to the
/boafrm/formIMEISetup endpoint to minimize the risk of exploitation.Exploit
Fix
Command Injection
OS Command Injection
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dwr-M920