CVE-2026-11339: D-Link DWR-M920 formUSSDSetup sub_41CF20 command injection
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict remote access to the device management interfaces (HTTP/HTTPS/SSH/etc.) from untrusted networks. Allow access only from trusted IPs or management VLANs and disable remote/remote-web management if not required.
- Compensating control
Block or apply a WAF rule at the network edge to deny or inspect HTTP(S) requests to the endpoint path /boafrm/formUSSDSetup (and related USSD-related parameters) to prevent exploitation of the command injection.
- Operational
Monitor device and network logs for requests to /boafrm/formUSSDSetup and for indicators of command injection activity. If exploitation is suspected, isolate the affected device(s) from the network and perform an incident investigation.
- Operational
Contact the vendor for remediation guidance and apply any firmware updates or official patches as soon as they are released; keep devices offline or isolated until fixes are applied.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-11339?
The severity of CVE-2026-11339 is rated as medium, with a score of 6.3.
How do I fix CVE-2026-11339?
To fix CVE-2026-11339, update your D-Link DWR-M920 firmware to version 1.1.51 or later.
What is the impact of CVE-2026-11339?
CVE-2026-11339 allows for remote command injection, potentially compromising the device's integrity.
Which devices are affected by CVE-2026-11339?
CVE-2026-11339 affects the D-Link DWR-M920 models running firmware versions up to 1.1.50.
Can CVE-2026-11339 be exploited remotely?
Yes, CVE-2026-11339 can be exploited remotely, making it critical for users to apply mitigations promptly.