SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90699

CRITICAL · CVSS 9.9 EPSS 1.59% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical vulnerability exists in D-Link DWR-M920 version 1.1.7, allowing remote attackers to execute OS command injection through the manipulation of the newPin argument in the formPinManageSetup function. This flaw poses a significant risk as it can be exploited without authentication, potentially leading to unauthorized access and control over affected devices. Organizations using this router model should prioritize immediate patching or mitigation to safeguard against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90699
Severity
CRITICAL
CVSS
9.9
EPSS
1.59%

Original NVD Description

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.