CVE-2026-11341 PUBLISHED

D-Link DWR-M920 formIMEISetup sub_412DA0 os command injection

Assigner: VulDB
Reserved: 05.06.2026 Published: 05.06.2026 Updated: 05.06.2026

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 5.3

Product Status

Vendor D-Link
Product DWR-M920
Versions
  • Version 1.1.0 is affected
  • Version 1.1.1 is affected
  • Version 1.1.2 is affected
  • Version 1.1.3 is affected
  • Version 1.1.4 is affected
  • Version 1.1.5 is affected
  • Version 1.1.6 is affected
  • Version 1.1.7 is affected
  • Version 1.1.8 is affected
  • Version 1.1.9 is affected
  • Version 1.1.10 is affected
  • Version 1.1.11 is affected
  • Version 1.1.12 is affected
  • Version 1.1.13 is affected
  • Version 1.1.14 is affected
  • Version 1.1.15 is affected
  • Version 1.1.16 is affected
  • Version 1.1.17 is affected
  • Version 1.1.18 is affected
  • Version 1.1.19 is affected
  • Version 1.1.20 is affected
  • Version 1.1.21 is affected
  • Version 1.1.22 is affected
  • Version 1.1.23 is affected
  • Version 1.1.24 is affected
  • Version 1.1.25 is affected
  • Version 1.1.26 is affected
  • Version 1.1.27 is affected
  • Version 1.1.28 is affected
  • Version 1.1.29 is affected
  • Version 1.1.30 is affected
  • Version 1.1.31 is affected
  • Version 1.1.32 is affected
  • Version 1.1.33 is affected
  • Version 1.1.34 is affected
  • Version 1.1.35 is affected
  • Version 1.1.36 is affected
  • Version 1.1.37 is affected
  • Version 1.1.38 is affected
  • Version 1.1.39 is affected
  • Version 1.1.40 is affected
  • Version 1.1.41 is affected
  • Version 1.1.42 is affected
  • Version 1.1.43 is affected
  • Version 1.1.44 is affected
  • Version 1.1.45 is affected
  • Version 1.1.46 is affected
  • Version 1.1.47 is affected
  • Version 1.1.48 is affected
  • Version 1.1.49 is affected
  • Version 1.1.50 is affected

Credits

  • kkff33 (VulDB User) reporter

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE