A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/LX-66-LX/cve-new/issues/1 | Exploit Issue Tracking |
| https://github.com/LX-66-LX/cve-new/issues/1#issue-3851345029 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.344652 | Permissions Required VDB Entry |
| https://vuldb.com/?id.344652 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.746400 | Third Party Advisory VDB Entry |
| https://www.dlink.com/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
No history.
Information
Published : 2026-02-07 12:15
Updated : 2026-02-12 16:21
NVD link : CVE-2026-2085
Mitre link : CVE-2026-2085
CVE.ORG link : CVE-2026-2085
JSON object : View
Products Affected
dlink
- dwr-m921_firmware
- dwr-m921
