📦 Dwr M920 Firmware

by Dlink

🔍 What is Dwr M920 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-15193

HIGH CVSS 8.8 Dec 29, 2025

A buffer overflow vulnerability in D-Link DWR-M920 routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter in the formParentControl function. This affects al...

CVE-2025-15190

HIGH CVSS 8.8 Dec 29, 2025

A stack-based buffer overflow vulnerability exists in D-Link DWR-M920 routers through firmware version 1.1.50. Remote attackers can exploit this by manipulating the ip6addr parameter in the formFilter...

CVE-2025-15189

HIGH CVSS 8.8 Dec 29, 2025

A buffer overflow vulnerability in D-Link DWR-M920 routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter. This affects all devices running firmware version...

CVE-2025-13553

HIGH CVSS 8.8 Nov 23, 2025

A remote buffer overflow vulnerability in D-Link DWR-M920 routers allows attackers to execute arbitrary code by manipulating the submit-url parameter. This affects devices running firmware version 1.1...

CVE-2025-13552

HIGH CVSS 8.8 Nov 23, 2025

A buffer overflow vulnerability in D-Link DIR-822K and DWR-M920 routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter in the /boafrm/formWlEncrypt endpoint...

CVE-2025-13550

HIGH CVSS 8.8 Nov 23, 2025

A buffer overflow vulnerability in D-Link DIR-822K and DWR-M920 routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter in the VPN configuration form. This a...

CVE-2025-13548

HIGH CVSS 8.8 Nov 23, 2025

A buffer overflow vulnerability in D-Link DIR-822K and DWR-M920 routers allows remote attackers to execute arbitrary code by manipulating the submit-url parameter in the /boafrm/formFirewallAdv endpoi...

CVE-2025-13547

HIGH CVSS 8.8 Nov 23, 2025

A memory corruption vulnerability in D-Link DIR-822K and DWR-M920 routers allows remote attackers to manipulate the 'submit-url' argument in the '/boafrm/formDdns' file, potentially leading to arbitra...

CVE-2025-13305

HIGH CVSS 8.8 Nov 17, 2025

A buffer overflow vulnerability in D-Link routers allows remote attackers to execute arbitrary code by manipulating the 'host' parameter in the traceroute diagnostic form. This affects D-Link DWR-M920...

CVE-2025-13304

HIGH CVSS 8.8 Nov 17, 2025

A buffer overflow vulnerability in D-Link routers allows remote attackers to execute arbitrary code by manipulating the 'host' parameter in the ping diagnostic form. This affects D-Link DWR-M920, DWR-...

CVE-2025-15192

MEDIUM CVSS 6.3 Dec 29, 2025

This CVE describes a command injection vulnerability in D-Link DWR-M920 routers that allows remote attackers to execute arbitrary commands by manipulating the fota_url parameter. The vulnerability aff...

CVE-2025-15191

MEDIUM CVSS 6.3 Dec 29, 2025

This CVE describes a command injection vulnerability in D-Link DWR-M920 routers that allows remote attackers to execute arbitrary commands by manipulating the fota_url parameter. The vulnerability aff...

CVE-2025-13306

MEDIUM CVSS 6.3 Nov 18, 2025

This CVE describes a command injection vulnerability in D-Link routers that allows attackers to execute arbitrary commands on affected devices by manipulating the 'host' parameter in the /boafrm/formD...