D-Link DWR-M921 OS Command Injection via formDiskCreateShare
First seen Sep 15, 2026 · Updated Sep 15, 2026 · CVSS 9.1
A critical OS command injection vulnerability has been disclosed in D-Link DWR-M921 routers (firmware 1.1.52), affecting the formDiskCreateShare functionality via the folderpath parameter. The flaw can be exploited remotely without authentication, and a public exploit is available, making mass exploitation likely. Organizations using these devices at network edges are at high risk of full device compromise.
Technical Analysis
CVE-2026-90703 is an OS command injection vulnerability (CVSS 9.1) in the 'system' function within /boafrm/formDiskCreateShare on D-Link DWR-M921 1.1.52 devices. The vulnerability arises from improper sanitization of the 'folderpath' parameter, which is passed to a system-level command execution routine on the embedded Linux OS running the router's web management interface. Because the attack is remotely exploitable and a working exploit is publicly disclosed, attackers can achieve arbitrary command execution with elevated privileges on the router, potentially enabling firmware modification, network pivoting, traffic interception, or botnet recruitment. If AI agent systems rely on network infrastructure using this router model for internet access, LAN routing, or as an edge gateway, compromise could allow attackers to intercept or manipulate agent-to-API traffic, exfiltrate API keys/credentials in transit, or redirect agent tool-use requests to malicious endpoints, representing a meaningful risk to agent pipeline integrity and confidentiality.
Affected Systems
D-Link DWR-M921 routers running firmware version 1.1.52; web management interface component /boafrm/formDiskCreateShare
Indicators of Compromise
- Endpoint: /boafrm/formDiskCreateShare
- Parameter: folderpath (malicious shell metacharacters/command payloads)
- No specific hashes, IPs, or domains publicly attributed at time of disclosure
Remediation Steps
- 1
Apply Vendor Patch
Check D-Link's security advisories for a firmware update addressing CVE-2026-90703 and apply it immediately once released.
- 2
Restrict Remote Management Access
Disable remote/WAN-facing administration on affected DWR-M921 devices and restrict management interface access to trusted internal networks only.
- 3
Network Segmentation
Isolate affected routers from critical infrastructure segments, including any hosts running AI agent workloads, RAG pipelines, or credential stores.
- 4
Input Validation Monitoring
Deploy IDS/IPS signatures to detect and block command injection attempts targeting the folderpath parameter and formDiskCreateShare endpoint.
- 5
Device Replacement/EOL Review
If no patch is issued, evaluate replacing end-of-life or unsupported D-Link devices with actively maintained hardware.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.