SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90702

CRITICAL · CVSS 9.1 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A critical vulnerability exists in the D-Link DWR-M921 router, specifically in the file system function of /boafrm/formDiskFormat, which allows for remote command injection through manipulated arguments. This flaw poses a significant risk as it can be exploited by attackers to execute arbitrary commands on the device, potentially compromising network security. Organizations using this router model should prioritize immediate patching or mitigation efforts to protect against potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90702
Severity
CRITICAL
CVSS
9.1
EPSS
N/A

Original NVD Description

A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.