---
id: CVE-2026-90699
title: A weakness has been identified in D-Link DWR-M920 1.1.7
summary: >-
  A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects
  the function sub_41E60C of the file /boafrm/formPinManageSetup. This
  manipulation of the argument newPin causes os command injection. The attack
  can be initiated…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-77
  - CWE-78
vendor: D-Link
product: DWR-M920
affected:
  - DWR-M920 1.1.7
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T20:56:48.220'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90699'
references:
  - url: 'https://github.com/H3rmesk1t/vulnerability-paper/issues/9'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90699'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/916259'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403232'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403232/cti'
    label: cna@vuldb.com
  - url: 'https://www.dlink.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-14T10:16:10.968071Z'
ingestedAt: '2026-09-14T15:23:07.463Z'
epss: 0.01593
epssPercentile: 0.74644
---

## Overview

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
