{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/dwr-m921-1.1.52/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:h:d-link:dwr-m921:1.1.52:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-90702"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DWR-M921 (1.1.52)"],"_cs_severities":["critical"],"_cs_tags":["cve","command-injection","network-security"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eD-Link DWR-M921 firmware version 1.1.52 is susceptible to a critical remote command injection vulnerability (CVE-2026-90702). The vulnerability resides within the 'system' function processing the /boafrm/formDiskFormat file. An attacker can reach this endpoint remotely and supply a maliciously crafted 'partition' argument, which is then passed directly to a system-level process without proper sanitization. Successful exploitation allows for unauthenticated arbitrary command execution, providing an attacker full control over the router. Given the availability of public exploit material, this vulnerability poses a significant risk to the integrity and confidentiality of networks relying on these devices. Defenders should prioritize identifying and patching these specific D-Link routers, as they are often used in SOHO environments and serve as critical gateways.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in full device compromise, potentially enabling attackers to intercept network traffic, modify configuration, or use the device as a pivot point for further lateral movement within the local network. As this is an edge device, compromise directly impacts the security perimeter of the affected organization or home office.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all D-Link DWR-M921 devices currently deployed within the environment and confirm firmware versions.\u003c/li\u003e\n\u003cli\u003eIf the firmware is at version 1.1.52, restrict management access to the web interface from untrusted networks until a patch is applied by the vendor.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) or network intrusion detection system (NIDS) signatures to monitor for HTTP POST requests directed at /boafrm/formDiskFormat containing command shell characters (e.g., ;, |, \u0026amp;, `) in the partition parameter.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-14T11:32:48Z","date_published":"2026-09-14T11:32:48Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90702/","summary":"A remote command injection vulnerability in the D-Link DWR-M921 router allows unauthenticated attackers to execute arbitrary OS commands by manipulating the partition argument in the formDiskFormat function.","title":"Command Injection Vulnerability in D-Link DWR-M921","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90702/"}],"language":"en","title":"CraftedSignal Threat Feed - DWR-M921 (1.1.52)","version":"https://jsonfeed.org/version/1.1"}