CVE-2026-11339: D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection

Published Jun 5, 2026
·
Updated

A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

Affected Software

3 affected components
D-Link DWR-M920<=1.1.50
All of the following
Dlink Dwr-m920 Firmware=1.1.50
Dlink Dwr-m920

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Restrict remote access to the device management interfaces (HTTP/HTTPS/SSH/etc.) from untrusted networks. Allow access only from trusted IPs or management VLANs and disable remote/remote-web management if not required.

  2. Compensating control

    Block or apply a WAF rule at the network edge to deny or inspect HTTP(S) requests to the endpoint path /boafrm/formUSSDSetup (and related USSD-related parameters) to prevent exploitation of the command injection.

  3. Operational

    Monitor device and network logs for requests to /boafrm/formUSSDSetup and for indicators of command injection activity. If exploitation is suspected, isolate the affected device(s) from the network and perform an incident investigation.

  4. Operational

    Contact the vendor for remediation guidance and apply any firmware updates or official patches as soon as they are released; keep devices offline or isolated until fixes are applied.

Event History

Jun 5, 2026
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-11339?

The severity of CVE-2026-11339 is rated as medium, with a score of 6.3.

2

How do I fix CVE-2026-11339?

To fix CVE-2026-11339, update your D-Link DWR-M920 firmware to version 1.1.51 or later.

3

What is the impact of CVE-2026-11339?

CVE-2026-11339 allows for remote command injection, potentially compromising the device's integrity.

4

Which devices are affected by CVE-2026-11339?

CVE-2026-11339 affects the D-Link DWR-M920 models running firmware versions up to 1.1.50.

5

Can CVE-2026-11339 be exploited remotely?

Yes, CVE-2026-11339 can be exploited remotely, making it critical for users to apply mitigations promptly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2026-11339 - D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection - SecAlerts