PT-2025-53718 · D Link · D-Link Dwr-M920

·

CVE-2025-15191

·

Published

2025-12-29

·

Updated

2025-12-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DWR-M920 versions up to 1.1.50
Description A flaw exists in D-Link DWR-M920 devices running versions up to 1.1.50. This issue involves the manipulation of the fota url argument within the sub 4155B4 function located in the file /boafrm/formLtefotaUpgradeFibocom, leading to command injection. Remote exploitation is possible. The exploit has been publicly released and could be used to compromise systems.
Recommendations Versions prior to 1.1.50 should be updated. As a temporary workaround, consider restricting access to the /boafrm/formLtefotaUpgradeFibocom file to minimize the risk of exploitation. Avoid using the fota url parameter until the issue is resolved.

Exploit

Fix

Special Elements Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-15191

Affected Products

D-Link Dwr-M920