<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>DWR-M921 (1.1.52) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dwr-m921-1.1.52/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 11:32:48 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dwr-m921-1.1.52/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection Vulnerability in D-Link DWR-M921</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90702/</link><pubDate>Mon, 14 Sep 2026 11:32:48 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90702/</guid><description>A remote command injection vulnerability in the D-Link DWR-M921 router allows unauthenticated attackers to execute arbitrary OS commands by manipulating the partition argument in the formDiskFormat function.</description><content:encoded><![CDATA[<p>D-Link DWR-M921 firmware version 1.1.52 is susceptible to a critical remote command injection vulnerability (CVE-2026-90702). The vulnerability resides within the 'system' function processing the /boafrm/formDiskFormat file. An attacker can reach this endpoint remotely and supply a maliciously crafted 'partition' argument, which is then passed directly to a system-level process without proper sanitization. Successful exploitation allows for unauthenticated arbitrary command execution, providing an attacker full control over the router. Given the availability of public exploit material, this vulnerability poses a significant risk to the integrity and confidentiality of networks relying on these devices. Defenders should prioritize identifying and patching these specific D-Link routers, as they are often used in SOHO environments and serve as critical gateways.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability results in full device compromise, potentially enabling attackers to intercept network traffic, modify configuration, or use the device as a pivot point for further lateral movement within the local network. As this is an edge device, compromise directly impacts the security perimeter of the affected organization or home office.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Inventory all D-Link DWR-M921 devices currently deployed within the environment and confirm firmware versions.</li>
<li>If the firmware is at version 1.1.52, restrict management access to the web interface from untrusted networks until a patch is applied by the vendor.</li>
<li>Deploy web application firewall (WAF) or network intrusion detection system (NIDS) signatures to monitor for HTTP POST requests directed at /boafrm/formDiskFormat containing command shell characters (e.g., ;, |, &amp;, `) in the partition parameter.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve</category><category>command-injection</category><category>network-security</category></item></channel></rss>