← לוח פגיעויות

CVE-2026-90704

בינונית 6.6

תיאור (מקור, אנגלית)

A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/formDiskPartition. Performing a manipulation of the argument devicename results in command injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

מדדים

CVSS 3.1
6.6 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CVSS 4.0
2.0 (LOW) מקור הציון: CNA CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
2% (אחוזון 100) נכון ל-2/10/2026
CWE
CWE-74, CWE-77

קישורים