CVE-2026-11341

Severity CVSS v4.0:
LOW
Type:
CWE-77 Command Injection
Publication date:
05/06/2026
Last modified:
05/06/2026

Description

A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.