Description
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Published: 2026-06-05
Score: 5.3 Medium
EPSS: 4.2% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dwr-m920
Dlink dwr-m920 Firmware
CPEs cpe:2.3:h:dlink:dwr-m920:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m920_firmware:1.1.50:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m920_firmware:1.1.70:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dwr-m920
Dlink dwr-m920 Firmware

Fri, 05 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Title D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
First Time appeared D-link
D-link dwr-m920
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:h:d-link:dwr-m920:*:*:*:*:*:*:*:*
Vendors & Products D-link
D-link dwr-m920
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Dwr-m920
Dlink Dwr-m920 Dwr-m920 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-05T19:28:05.511Z

Reserved: 2026-06-04T15:40:34.401Z

Link: CVE-2026-10878

cve-icon Vulnrichment

Updated: 2026-06-05T19:27:59.067Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-05T00:16:59.730

Modified: 2026-06-05T16:48:39.577

Link: CVE-2026-10878

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T04:00:15Z

Weaknesses