CVE-2026-10878
MEDIUM
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Jun 05, 2026
Vendor
unknown
Description
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.