CVE-2026-90704
MEDIUM
NVD
CVSS Score
6.6
Severity
MEDIUM
Published
Sep 14, 2026
Vendor
unknown
Description
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.