PT-2026-6903 · D Link · D-Link Dwr-M921

·

CVE-2026-2085

·

Published

2026-02-07

·

Updated

2026-02-07

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DWR-M921 version 1.1.50
Description A security issue exists in D-Link DWR-M921 version 1.1.50 related to command injection. The issue is located in the USSD Configuration component, specifically within the sub 419F20 function of the /boafrm/formUSSDSetup file. Manipulation of the ussdValue argument can lead to command injection. This attack can be initiated remotely. The exploit has been publicly disclosed.
Recommendations Apply a software update that addresses the vulnerability in the USSD Configuration component. As a temporary workaround, restrict access to the /boafrm/formUSSDSetup file. Avoid using the ussdValue parameter until the issue is resolved.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-2085

Affected Products

D-Link Dwr-M921