Medium severity6.3NVD Advisory· Published Jun 5, 2026· Updated Jun 9, 2026
CVE-2026-11339
CVE-2026-11339
Description
A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:dlink:dwr-m920_firmware:1.1.50:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/7u7777/Dlink/blob/DWR-M920/formUSSDSetup.mdnvdExploitMitigationThird Party Advisory
- vuldb.com/cve/CVE-2026-11339nvdThird Party AdvisoryVDB Entry
- vuldb.com/submit/832579nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/368881nvdThird Party AdvisoryVDB Entry
- vuldb.com/vuln/368881/ctinvdPermissions RequiredVDB Entry
- www.dlink.comnvdProduct
News mentions
1- D-Link DWR-M920: Three Command Injection Flaws Disclosed TogetherVypr Intelligence · Jun 5, 2026