D-Link Dwr-M920 vulnerabilities
17 known vulnerabilities affecting d-link/dwr-m920.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-13306P2HIGHCVSS 8.8v1.1.52025-11-18
CVE-2025-13306 [HIGH] CWE-74 CVE-2025-13306: A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5
A security vulnerability has been detected in D-Link DWR-M920, DWR-M921, DIR-822K and DIR-825M 1.1.5. Impacted is the function system of the file /boafrm/formDebugDiagnosticRun. The manipulation of the argument host leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
nvd
CVE-2025-13305P2CRITICALCVSS 9.8v1.01.072025-11-17
CVE-2025-13305 [CRITICAL] CWE-119 CVE-2025-13305: A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07
A weakness has been identified in D-Link DWR-M920, DWR-M921, DWR-M960, DIR-822K and DIR-825M 1.01.07. This issue affects some unknown processing of the file /boafrm/formTracerouteDiagnosticRun. Executing manipulation of the argument host can lead to buffer overflow. The attack may be launched remotely. The exploit has been made available to the pu
nvd
CVE-2026-10878P2HIGHCVSS 8.8v1.1.50v1.1.702026-06-05
CVE-2026-10878 [HIGH] CWE-74 CVE-2026-10878: A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 o
A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd
CVE-2025-15191P2HIGHCVSS 8.8v1.1.0v1.1.1+49 more2025-12-29
CVE-2025-15191 [HIGH] CWE-74 CVE-2025-15191: A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function
A weakness has been identified in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_4155B4 of the file /boafrm/formLtefotaUpgradeFibocom. This manipulation of the argument fota_url causes command injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be exploited.
nvd
CVE-2025-15192P2HIGHCVSS 8.8v1.1.0v1.1.1+49 more2025-12-29
CVE-2025-15192 [HIGH] CWE-74 CVE-2025-15192: A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is
A security vulnerability has been detected in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_415328 of the file /boafrm/formLtefotaUpgradeQuectel. Such manipulation of the argument fota_url leads to command injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
nvd
CVE-2026-11339P2HIGHCVSS 8.8v1.1.0v1.1.1+49 more2026-06-05
CVE-2026-11339 [HIGH] CWE-74 CVE-2026-11339: A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function s
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
nvd
CVE-2025-15190P2HIGHCVSS 8.8v1.1.0v1.1.1+49 more2025-12-29
CVE-2025-15190 [HIGH] CWE-119 CVE-2025-15190: A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50. Impacted is the function sub_42
A security flaw has been discovered in D-Link DWR-M920 up to 1.1.50. Impacted is the function sub_42261C of the file /boafrm/formFilter. The manipulation of the argument ip6addr results in stack-based buffer overflow. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
nvd
CVE-2025-13548P2HIGHCVSS 8.8v1.00_20250513164613v1.1.502025-11-23
CVE-2025-13548 [HIGH] CWE-119 CVE-2025-13548: A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vuln
A vulnerability has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This vulnerability affects unknown code of the file /boafrm/formFirewallAdv. Such manipulation of the argument submit-url leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
nvd
CVE-2025-13553P2HIGHCVSS 8.8v1.1.502025-11-23
CVE-2025-13553 [HIGH] CWE-119 CVE-2025-13553: A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of th
A weakness has been identified in D-Link DWR-M920 1.1.50. This affects the function sub_41C7FC of the file /boafrm/formPinManageSetup. This manipulation of the argument submit-url causes buffer overflow. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be exploited.
nvd
CVE-2025-15193P2HIGHCVSS 8.8v1.1.0v1.1.1+49 more2025-12-29
CVE-2025-15193 [HIGH] CWE-119 CVE-2025-15193: A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 o
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. This affects the function sub_423848 of the file /boafrm/formParentControl. Performing manipulation of the argument submit-url results in buffer overflow. The attack is possible to be carried out remotely. The exploit is now public and may be used.
nvd
CVE-2025-15189P2HIGHCVSS 8.8v1.1.0v1.1.1+49 more2025-12-29
CVE-2025-15189 [HIGH] CWE-119 CVE-2025-15189: A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_
A vulnerability was identified in D-Link DWR-M920 up to 1.1.50. This issue affects the function sub_464794 of the file /boafrm/formDefRoute. The manipulation of the argument submit-url leads to buffer overflow. The attack may be initiated remotely. The exploit is publicly available and might be used.
nvd
CVE-2025-13304P2HIGHCVSS 8.8v1.01.07v1.1.472025-11-17
CVE-2025-13304 [HIGH] CWE-119 CVE-2025-13304: A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.
A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit has been released to the public a
nvd
CVE-2025-13552P2HIGHCVSS 8.8v1.00_20250513164613v1.1.502025-11-23
CVE-2025-13552 [HIGH] CWE-119 CVE-2025-13552: A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The
A security flaw has been discovered in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The impacted element is an unknown function of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url results in buffer overflow. The attack may be performed from remote. The exploit has been released to the public and may be exploited.
nvd
CVE-2025-13550P2HIGHCVSS 8.8v1.00_20250513164613v1.1.502025-11-23
CVE-2025-13550 [HIGH] CWE-119 CVE-2025-13550: A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted
A vulnerability was determined in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. Impacted is an unknown function of the file /boafrm/formVpnConfigSetup. Executing manipulation of the argument submit-url can lead to buffer overflow. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
nvd
CVE-2025-13551P2HIGHCVSS 8.8v1.00_20250513164613v1.1.502025-11-23
CVE-2025-13551 [HIGH] CWE-119 CVE-2025-13551: A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affec
A vulnerability was identified in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. The affected element is an unknown function of the file /boafrm/formWanConfigSetup. The manipulation of the argument submit-url leads to buffer overflow. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.
nvd
CVE-2025-13547P3HIGHCVSS 8.8v1.00_20250513164613v1.1.502025-11-23
CVE-2025-13547 [HIGH] CWE-119 CVE-2025-13547: A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an un
A flaw has been found in D-Link DIR-822K and DWR-M920 1.00_20250513164613/1.1.50. This affects an unknown part of the file /boafrm/formDdns. This manipulation of the argument submit-url causes memory corruption. The attack may be initiated remotely. The exploit has been published and may be used.
nvd
CVE-2026-11341P3MEDIUMCVSS 6.3v1.1.0v1.1.1+49 more2026-06-05
CVE-2026-11341 [MEDIUM] CWE-77 CVE-2026-11341: A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412D
A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of the argument IMEI_value causes os command injection. The attack can be initiated remotely. The exploit has been published and may be used.
nvd