A security vulnerability has been detected in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used.
References
| Link | Resource |
|---|---|
| https://github.com/LX-66-LX/cve-new/issues/1 | Exploit Issue Tracking |
| https://github.com/LX-66-LX/cve-new/issues/1#issue-3851345029 | Exploit Issue Tracking |
| https://vuldb.com/?ctiid.344652 | Permissions Required VDB Entry |
| https://vuldb.com/?id.344652 | Third Party Advisory VDB Entry |
| https://vuldb.com/?submit.746400 | Third Party Advisory VDB Entry |
| https://www.dlink.com/ | Product |
Configurations
Configuration 1 (hide)
| AND |
|
History
12 Feb 2026, 16:21
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:dlink:dwr-m921_firmware:1.1.50:*:*:*:*:*:*:* cpe:2.3:h:dlink:dwr-m921:-:*:*:*:*:*:*:* |
|
| First Time |
Dlink
Dlink dwr-m921 Firmware Dlink dwr-m921 |
|
| References | () https://github.com/LX-66-LX/cve-new/issues/1 - Exploit, Issue Tracking | |
| References | () https://github.com/LX-66-LX/cve-new/issues/1#issue-3851345029 - Exploit, Issue Tracking | |
| References | () https://vuldb.com/?ctiid.344652 - Permissions Required, VDB Entry | |
| References | () https://vuldb.com/?id.344652 - Third Party Advisory, VDB Entry | |
| References | () https://vuldb.com/?submit.746400 - Third Party Advisory, VDB Entry | |
| References | () https://www.dlink.com/ - Product |
07 Feb 2026, 12:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-07 12:15
Updated : 2026-02-12 16:21
NVD link : CVE-2026-2085
Mitre link : CVE-2026-2085
CVE.ORG link : CVE-2026-2085
JSON object : View
Products Affected
dlink
- dwr-m921_firmware
- dwr-m921
