PT-2025-53723 · D Link · D-Link Dwr-M920

Panda_0X1

·

Published

2025-12-29

·

Updated

2025-12-30

·

CVE-2025-15192

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions D-Link DWR-M920 versions up to 1.1.50
Description A security issue exists in D-Link DWR-M920. Manipulation of the fota url argument within the sub 415328 function of the /boafrm/formLtefotaUpgradeQuectel file can lead to command injection. This attack can be carried out remotely. The exploit for this issue has been publicly disclosed.
Recommendations Versions prior to 1.1.50 should be updated. As a temporary workaround, consider restricting access to the /boafrm/formLtefotaUpgradeQuectel file to minimize the risk of exploitation. Avoid using the fota url parameter in the affected function until the issue is resolved.

Exploit

Fix

Special Elements Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-15192

Affected Products

D-Link Dwr-M920