CVE-2026-2085 | D-Link DWR-M921 1.1.50 USSD Configuration Endpoint /boafrm/formUSSDSetup sub_419F20 ussdValue command injection (EUVD-2026-5728 / WID-SEC-2026-0340)
A vulnerability classified as critical has been found in D-Link DWR-M921 1.1.50. Affected is the function sub_419F20 of the file /boafrm/formUSSDSetup of the component USSD Configuration Endpoint. The manipulation of the argument ussdValue leads to command injection.
This vulnerability is documented as CVE-2026-2085. The attack can be initiated remotely. Additionally, an exploit exists.