PT-2025-53718 · D Link · D-Link Dwr-M920
Panda_0X1
·
Published
2025-12-29
·
Updated
2025-12-30
·
CVE-2025-15191
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DWR-M920 versions up to 1.1.50
Description
A flaw exists in D-Link DWR-M920 devices running versions up to 1.1.50. This issue involves the manipulation of the
fota url argument within the sub 4155B4 function located in the file /boafrm/formLtefotaUpgradeFibocom, leading to command injection. Remote exploitation is possible. The exploit has been publicly released and could be used to compromise systems.Recommendations
Versions prior to 1.1.50 should be updated. As a temporary workaround, consider restricting access to the /boafrm/formLtefotaUpgradeFibocom file to minimize the risk of exploitation. Avoid using the
fota url parameter until the issue is resolved.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dwr-M920