CyberRota Analysis
AI-GeneratedA critical vulnerability exists in D-Link DWR-M920 version 1.1.7, allowing remote attackers to execute OS command injection through the manipulation of the newPin argument in the formPinManageSetup function. This flaw poses a significant risk as it can be exploited without authentication, potentially leading to unauthorized access and control over affected devices. Organizations using this router model should prioritize immediate patching or mitigation to safeguard against potential exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.