PT-2025-53723 · D Link · D-Link Dwr-M920
Panda_0X1
·
Published
2025-12-29
·
Updated
2025-12-30
·
CVE-2025-15192
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
D-Link DWR-M920 versions up to 1.1.50
Description
A security issue exists in D-Link DWR-M920. Manipulation of the
fota url argument within the sub 415328 function of the /boafrm/formLtefotaUpgradeQuectel file can lead to command injection. This attack can be carried out remotely. The exploit for this issue has been publicly disclosed.Recommendations
Versions prior to 1.1.50 should be updated. As a temporary workaround, consider restricting access to the
/boafrm/formLtefotaUpgradeQuectel file to minimize the risk of exploitation. Avoid using the fota url parameter in the affected function until the issue is resolved.Exploit
Fix
Special Elements Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
D-Link Dwr-M920