CVE-2025-15192Medium· 6.3▾ SunlitA security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command inject…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 34.7 · likelihood 0.8 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
4.1%
A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
dwr-m920_firmware <= 1.1.50Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14884High· 7.2A vulnerability was detected in D-Link DIR-605 202WWB03
CVE-2025-15191Medium· 6.3A weakness has been identified in D-Link DWR-M920 up to 1.1.50
CVE-2025-15391Medium· 6.3A weakness has been identified in D-Link DIR-806A 100CNb11
CVE-2025-11098Medium· 6.3A vulnerability was found in D-Link DIR-823X 250416
CVE-2025-11095Medium· 6.3A vulnerability was detected in D-Link DIR-823X 250416
CVE-2025-10634Medium· 6.3A weakness has been identified in D-Link DIR-823X 240126/240802/250416