VulnerabilityAnalyzed
CVE-2026-2085
A security vulnerability has been detected in D-Link DWR-M921 1.1.50.
HIGH 7.3EPSS 4.52%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.52%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
- CVSS 4.0
- 7.3 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 4.52% probability · 91th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-74, CWE-77
- Affected
- dlink/dwr-m921 firmware
- Source
- cna@vuldb.com
References
- https://github.com/LX-66-LX/cve-new/issues/1Exploit, Issue Tracking
- https://github.com/LX-66-LX/cve-new/issues/1#issue-3851345029Exploit, Issue Tracking
- https://vuldb.com/?ctiid.344652Permissions Required, VDB Entry
- https://vuldb.com/?id.344652Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.746400Third Party Advisory, VDB Entry
- https://www.dlink.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.