CVE-2026-11341
MEDIUM
NVD
CVSS Score
6.3
Severity
MEDIUM
Published
Jun 05, 2026
Vendor
unknown
Description
A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.