PT-2026-47006 · D Link · Dwr-M920

·

CVE-2026-11341

·

Published

2026-05-18

·

Updated

2026-06-05

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions D-Link DWR-M920 versions prior to 1.1.51
Description A flaw in the sub 412DA0() function within the /boafrm/formIMEISetup file allows for remote OS command injection. This occurs through the manipulation of the IMEI value argument.
Recommendations Update to a version later than 1.1.50. As a temporary workaround, restrict access to the /boafrm/formIMEISetup endpoint to minimize the risk of exploitation.

Exploit

Fix

Command Injection

OS Command Injection

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07968
CVE-2026-11341

Affected Products

Dwr-M920