Vulnerability Description
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dwr-M920 Firmware | 1.1.50 |
| Dlink | Dwr-M920 | - |
Related Weaknesses (CWE)
References
- https://github.com/7u7777/Dlink/blob/DWR-M920/formSmsManage.mdExploitThird Party Advisory
- https://vuldb.com/cve/CVE-2026-10878Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/832154Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/368368Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/368368/ctiPermissions RequiredVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2026-10878?
CVE-2026-10878 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in ...
How severe is CVE-2026-10878?
CVE-2026-10878 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-10878?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dwr-M920 Firmware, Dlink Dwr-M920.