D Link Dwr M921
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in D Link Dwr M921.
By the Year
In 2026 there have been 5 vulnerabilities in D Link Dwr M921 with an average score of 6.8 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 5 | 6.82 |
It may take a day or so for new Dwr M921 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent D Link Dwr M921 Security Vulnerabilities
D-Link DWR-M921 1.1.52 OS Command Injection via formWsc TargetAPSsid
CVE-2026-90706
5.1 - Medium
- September 14, 2026
A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc. The manipulation of the argument targetAPSsid leads to os command injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
Shell injection
D-Link DWR-M921 1.1.52 FormsysCmd OS cmd injection via sysCmd
CVE-2026-90705
5.1 - Medium
- September 14, 2026
A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/formsysCmd of the component Boa Dispatch Table. Executing a manipulation of the argument sysCmd can lead to os command injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Shell injection
D-Link DWR-M921 1.1.52 Command Injection via devicename /boafrm/formDiskPartition
CVE-2026-90704
5.1 - Medium
- September 14, 2026
A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Command Injection
D-Link DWR-M921 1.1.52 OS Command Injection via formDiskCreateShare
CVE-2026-90703
9.4 - Critical
- September 14, 2026
A vulnerability has been found in D-Link DWR-M921 1.1.52. The affected element is the function system of the file /boafrm/formDiskCreateShare. Such manipulation of the argument folderpath leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Shell injection
Command Injection via /boafrm/formDiskFormat in D-Link DWR-M921 1.1.52 Remote Exploit
CVE-2026-90702
9.4 - Critical
- September 14, 2026
A flaw has been found in D-Link DWR-M921 1.1.52. Impacted is the function system of the file /boafrm/formDiskFormat. This manipulation of the argument partition causes os command injection. The attack may be initiated remotely. The exploit has been published and may be used.
Shell injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for D Link Dwr M921 or by D Link? Click the Watch button to subscribe.