criticalZero-Day

D-Link DWR-M921 OS Command Injection via formDiskFormat

First seen Sep 15, 2026 · Updated Sep 15, 2026 · CVSS 9.1

iotroutercommand-injectiond-linkunauthenticated-rcepublic-exploit

A critical unauthenticated OS command injection vulnerability exists in D-Link DWR-M921 firmware version 1.1.52, affecting the /boafrm/formDiskFormat endpoint via the 'partition' parameter. A public exploit is available, allowing remote attackers to execute arbitrary system commands on affected devices with no authentication required.

Technical Analysis

The vulnerability resides in the 'system' function invoked by the /boafrm/formDiskFormat handler on the Boa web server embedded in D-Link DWR-M921 1.1.52 firmware. Improper sanitization of the 'partition' argument allows attackers to inject arbitrary shell commands that are executed with the privileges of the web server process, typically root on embedded Linux devices. Because the exploit is remotely reachable and requires no authentication, it can be weaponized for full device takeover, botnet recruitment, or as a network pivot point. Given the public availability of exploit code, mass scanning and automated exploitation attempts are likely imminent. Organizations deploying AI agents or edge inference workloads on or behind vulnerable D-Link routers face risk of network-level compromise, traffic interception, or credential/API-key theft from agent traffic traversing the compromised device, warranting inclusion in agent-facing network security reviews.

Affected Systems

D-Link DWR-M921 routers running firmware version 1.1.52, specifically the Boa web server component handling /boafrm/formDiskFormat requests

Indicators of Compromise

  • Endpoint: /boafrm/formDiskFormat
  • Parameter: partition (command injection vector)
  • Note: No specific hashes, IPs, or domains published at time of disclosure

Remediation Steps

  1. 1

    Apply Firmware Update

    Check D-Link's security advisory page for a patched firmware release addressing this command injection flaw and apply it immediately.

  2. 2

    Restrict Web Interface Access

    Disable remote/WAN management access to the router's web administration interface and restrict access to trusted internal networks only.

  3. 3

    Network Segmentation

    Isolate IoT and edge networking devices from segments running AI agent workloads, RAG pipelines, or systems holding sensitive API keys.

  4. 4

    Monitor for Exploitation

    Deploy IDS/IPS signatures targeting requests to /boafrm/formDiskFormat with anomalous partition parameter values, and monitor for unexpected outbound connections from affected devices.

  5. 5

    Device Replacement

    If no patch is available, consider decommissioning or replacing the affected end-of-support device model.

CVE / Advisory IDs

CVE-2026-90702

Industries Most Exposed

TelecommunicationsConsumer/Home NetworkingSmall Business ITManaged Service Providers

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.