CVE-2026-2168 | D-Link DWR-M921 1.1.50 formLtefotaUpgradeQuectel sub_419920 fota_url command injection (EUVD-2026-5781)
A vulnerability was found in D-Link DWR-M921 1.1.50. It has been rated as critical. This affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection.
The identification of this vulnerability is CVE-2026-2168. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.