VYPR
Medium severity6.3NVD Advisory· Published Jun 5, 2026· Updated Jun 5, 2026

CVE-2026-10878

CVE-2026-10878

Description

A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:o:dlink:dwr-m920_firmware:1.1.50:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:o:dlink:dwr-m920_firmware:1.1.50:*:*:*:*:*:*:*
    • cpe:2.3:o:dlink:dwr-m920_firmware:1.1.70:*:*:*:*:*:*:*
  • Dlink/DWR-M920llm-create
    Range: 1.1.50/1.1.70
  • Dlink/Dlinkllm-fuzzy
    Range: 1.1.50/1.1.70

Patches

Vulnerability mechanics

References

6

News mentions

1