CVE-2026-90699 Details
Description
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
An OS command injection vulnerability has been identified in the D-Link DWR-M920 router, specifically in firmware version 1.1.7 for hardware B2. The issue arises in the formPinManageSetup handler, where the newPin parameter is accepted without proper validation or sanitization. This vulnerability can be exploited remotely by authenticated users, allowing them to execute arbitrary commands on the device with root privileges.
Users are advised to update to a version of the D-Link DWR-M920 router that addresses this vulnerability. Consult the D-Link support website or contact D-Link customer service for guidance on obtaining the latest firmware.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 14, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/H3rmesk1t/vulnerability-paper/issues/9 | [email protected] | ExploitIssue TrackingTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-90699 | [email protected] | Content Wall |
| https://vuldb.com/submit/916259 | [email protected] | Permission Required |
| https://vuldb.com/vuln/403232 | [email protected] | Content Wall |
| https://vuldb.com/vuln/403232/cti | [email protected] | Content Wall |
| https://www.dlink.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| D-Link DWR-M920 | 1.1.7 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 14, 2026 | New CVE Received | [email protected] |
Volerion