CVE-2025-15192
EUVD-2025-20558029.12.2025, 15:16
A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dlink | dwr-m920_firmware | 𝑥 ≤ 1.1.50 |
𝑥
= Vulnerable software versions
References