PT-2025-53718 · D Link · D-Link Dwr-M920

Panda_0X1

·

Published

2025-12-29

·

Updated

2025-12-30

·

CVE-2025-15191

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DWR-M920 versions up to 1.1.50
Description A flaw exists in D-Link DWR-M920 devices running versions up to 1.1.50. This issue involves the manipulation of the fota url argument within the sub 4155B4 function located in the file /boafrm/formLtefotaUpgradeFibocom, leading to command injection. Remote exploitation is possible. The exploit has been publicly released and could be used to compromise systems.
Recommendations Versions prior to 1.1.50 should be updated. As a temporary workaround, consider restricting access to the /boafrm/formLtefotaUpgradeFibocom file to minimize the risk of exploitation. Avoid using the fota url parameter until the issue is resolved.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15191

Affected Products

D-Link Dwr-M920