CVE-2026-11341: D-Link Dwr-m920
Medium severity, CVSS 6.3. EPSS: 1% chance of exploitation in the next 30 days.
A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.
Affected products
- D-Link Dwr-m920: version 1.1.0 only; version 1.1.1 only; version 1.1.2 only; version 1.1.3 only; version 1.1.4 only; version 1.1.5 only; …
Published 2026-06-05. Last modified 2026-06-17.