criticalZero-Day

D-Link DWR-M921 OS Command Injection via formDiskCreateShare

First seen Sep 15, 2026 · Updated Sep 15, 2026 · CVSS 9.1

os-command-injectiond-linkrouteriotunauthenticated-rcepublic-exploitnetwork-device

A critical OS command injection vulnerability has been disclosed in D-Link DWR-M921 routers (firmware 1.1.52), affecting the formDiskCreateShare functionality via the folderpath parameter. The flaw can be exploited remotely without authentication, and a public exploit is available, making mass exploitation likely. Organizations using these devices at network edges are at high risk of full device compromise.

Technical Analysis

CVE-2026-90703 is an OS command injection vulnerability (CVSS 9.1) in the 'system' function within /boafrm/formDiskCreateShare on D-Link DWR-M921 1.1.52 devices. The vulnerability arises from improper sanitization of the 'folderpath' parameter, which is passed to a system-level command execution routine on the embedded Linux OS running the router's web management interface. Because the attack is remotely exploitable and a working exploit is publicly disclosed, attackers can achieve arbitrary command execution with elevated privileges on the router, potentially enabling firmware modification, network pivoting, traffic interception, or botnet recruitment. If AI agent systems rely on network infrastructure using this router model for internet access, LAN routing, or as an edge gateway, compromise could allow attackers to intercept or manipulate agent-to-API traffic, exfiltrate API keys/credentials in transit, or redirect agent tool-use requests to malicious endpoints, representing a meaningful risk to agent pipeline integrity and confidentiality.

Affected Systems

D-Link DWR-M921 routers running firmware version 1.1.52; web management interface component /boafrm/formDiskCreateShare

Indicators of Compromise

  • Endpoint: /boafrm/formDiskCreateShare
  • Parameter: folderpath (malicious shell metacharacters/command payloads)
  • No specific hashes, IPs, or domains publicly attributed at time of disclosure

Remediation Steps

  1. 1

    Apply Vendor Patch

    Check D-Link's security advisories for a firmware update addressing CVE-2026-90703 and apply it immediately once released.

  2. 2

    Restrict Remote Management Access

    Disable remote/WAN-facing administration on affected DWR-M921 devices and restrict management interface access to trusted internal networks only.

  3. 3

    Network Segmentation

    Isolate affected routers from critical infrastructure segments, including any hosts running AI agent workloads, RAG pipelines, or credential stores.

  4. 4

    Input Validation Monitoring

    Deploy IDS/IPS signatures to detect and block command injection attempts targeting the folderpath parameter and formDiskCreateShare endpoint.

  5. 5

    Device Replacement/EOL Review

    If no patch is issued, evaluate replacing end-of-life or unsupported D-Link devices with actively maintained hardware.

CVE / Advisory IDs

CVE-2026-90703

Industries Most Exposed

TelecommunicationsConsumer ElectronicsSmall/Medium BusinessManaged Service ProvidersCritical Infrastructure

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.