CVE-2026-10878
EUVD-2026-3477505.06.2026, 00:16
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| dlink | dwr-m920_firmware | 1.1.50 |
| dlink | dwr-m920_firmware | 1.1.70 |
𝑥
= Vulnerable software versions