Vulnerability Description
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dlink | Dwr-M920 Firmware | 1.1.50 |
| Dlink | Dwr-M920 | - |
Related Weaknesses (CWE)
References
- https://github.com/7u7777/Dlink/blob/DWR-M920/formUSSDSetup.mdExploitMitigationThird Party Advisory
- https://vuldb.com/cve/CVE-2026-11339Third Party AdvisoryVDB Entry
- https://vuldb.com/submit/832579Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/368881Third Party AdvisoryVDB Entry
- https://vuldb.com/vuln/368881/ctiPermissions RequiredVDB Entry
- https://www.dlink.com/Product
FAQ
What is CVE-2026-11339?
CVE-2026-11339 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in c...
How severe is CVE-2026-11339?
CVE-2026-11339 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-11339?
Check the references section above for vendor advisories and patch information. Affected products include: Dlink Dwr-M920 Firmware, Dlink Dwr-M920.