📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Information Technology CRITICAL 49m Global vulnerability Enterprise Software and Cloud Services HIGH 1h Global vulnerability Information Technology, Security Infrastructure CRITICAL 1h Global vulnerability Industrial Control Systems / Manufacturing HIGH 3h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global vulnerability Software/Cloud Services HIGH 3h Global vulnerability Network Infrastructure HIGH 4h Global vulnerability Mobile Device Management / Enterprise Security CRITICAL 4h Global vulnerability Operating Systems/Security Software CRITICAL 5h Global vulnerability Software Development and Technology CRITICAL 5h Global vulnerability Information Technology CRITICAL 49m Global vulnerability Enterprise Software and Cloud Services HIGH 1h Global vulnerability Information Technology, Security Infrastructure CRITICAL 1h Global vulnerability Industrial Control Systems / Manufacturing HIGH 3h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global vulnerability Software/Cloud Services HIGH 3h Global vulnerability Network Infrastructure HIGH 4h Global vulnerability Mobile Device Management / Enterprise Security CRITICAL 4h Global vulnerability Operating Systems/Security Software CRITICAL 5h Global vulnerability Software Development and Technology CRITICAL 5h Global vulnerability Information Technology CRITICAL 49m Global vulnerability Enterprise Software and Cloud Services HIGH 1h Global vulnerability Information Technology, Security Infrastructure CRITICAL 1h Global vulnerability Industrial Control Systems / Manufacturing HIGH 3h Global general Artificial Intelligence and Cybersecurity MEDIUM 3h Global vulnerability Software/Cloud Services HIGH 3h Global vulnerability Network Infrastructure HIGH 4h Global vulnerability Mobile Device Management / Enterprise Security CRITICAL 4h Global vulnerability Operating Systems/Security Software CRITICAL 5h Global vulnerability Software Development and Technology CRITICAL 5h
Vulnerabilities

CVE-2026-11339

Medium
CWE-74 — Weakness Type
Published: Jun 5, 2026  ·  Modified: Jun 8, 2026  ·  Source: NVD
CVSS v3
6.3
🔗 NVD Official
📄 Description (English)

A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the argument ussdValue results in command injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

🤖 AI Executive Summary

A command injection vulnerability exists in D-Link DWR-M920 routers (up to firmware 1.1.50) affecting the USSD setup function. The vulnerability allows remote attackers to execute arbitrary commands with medium severity (CVSS 6.3). While no public exploit is currently available, the vulnerability details are public, increasing the risk of exploitation.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 5, 2026 22:36
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi telecommunications infrastructure, particularly STC and other ISPs utilizing D-Link DWR-M920 routers for residential and small business connectivity. Government agencies and critical infrastructure operators using these devices for network access are at risk. Banking and financial institutions relying on these routers for branch connectivity could face network compromise. Healthcare facilities using these devices for network access may experience service disruption. The vulnerability enables remote command execution, potentially leading to network reconnaissance, lateral movement, and data exfiltration.
🏢 Affected Saudi Sectors
Telecommunications (STC, Zain, Mobily) Internet Service Providers Government Agencies Banking and Financial Services Healthcare Critical Infrastructure Small Business Networks
⚖️ Saudi Risk Score (AI)
6.8
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Identify all D-Link DWR-M920 devices in your network using network scanning tools
2. Restrict access to the /boafrm/formUSSDSetup endpoint using firewall rules
3. Disable remote management features if not required
4. Implement network segmentation to isolate affected devices

Patching Guidance:
1. Contact D-Link support for firmware updates beyond version 1.1.50
2. Monitor D-Link security advisories for patch availability
3. Establish a firmware update schedule once patches are released

Compensating Controls:
1. Implement Web Application Firewall (WAF) rules to block malicious USSD parameter values
2. Deploy intrusion detection/prevention systems (IDS/IPS) to monitor for command injection patterns
3. Restrict administrative access to router management interfaces to trusted IP ranges only
4. Enable logging and monitoring of all /boafrm/formUSSDSetup requests
5. Implement rate limiting on the vulnerable endpoint

Detection Rules:
1. Monitor for HTTP POST requests to /boafrm/formUSSDSetup with special characters (|, ;, &, $, `, etc.) in ussdValue parameter
2. Alert on any successful command execution attempts following USSD setup requests
3. Track firmware versions of D-Link DWR-M920 devices and flag those below 1.1.50
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع أجهزة D-Link DWR-M920 في شبكتك باستخدام أدوات المسح
2. تقييد الوصول إلى نقطة نهاية /boafrm/formUSSDSetup باستخدام قواعد جدار الحماية
3. تعطيل ميزات الإدارة البعيدة إذا لم تكن مطلوبة
4. تنفيذ تقسيم الشبكة لعزل الأجهزة المتأثرة

إرشادات التصحيح:
1. الاتصال بدعم D-Link للحصول على تحديثات البرامج الثابتة بعد الإصدار 1.1.50
2. مراقبة تنبيهات أمان D-Link لتوفر التصحيحات
3. إنشاء جدول زمني لتحديث البرامج الثابتة عند توفر التصحيحات

الضوابط البديلة:
1. تنفيذ قواعد جدار تطبيقات الويب (WAF) لحجب قيم معاملات USSD الضارة
2. نشر أنظمة كشف/منع الاختراق (IDS/IPS) لمراقبة أنماط حقن الأوامر
3. تقييد الوصول الإداري إلى واجهات إدارة الموجهات على نطاقات IP موثوقة فقط
4. تفعيل تسجيل ومراقبة جميع طلبات /boafrm/formUSSDSetup
5. تنفيذ تحديد معدل على نقطة النهاية الضعيفة

قواعد الكشف:
1. مراقبة طلبات HTTP POST إلى /boafrm/formUSSDSetup بأحرف خاصة (|، ;، &، $، `، إلخ) في معامل ussdValue
2. التنبيه على أي محاولات تنفيذ أوامر ناجحة بعد طلبات إعداد USSD
3. تتبع إصدارات البرامج الثابتة لأجهزة D-Link DWR-M920 والإشارة إلى تلك التي تقل عن 1.1.50
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities ECC 2024 A.14.2.1 - Secure development policy ECC 2024 A.12.2.1 - Monitoring and logging of network access
🔵 SAMA CSF
SAMA CSF ID.BE-1 - Asset management SAMA CSF PR.DS-6 - Integrity checking mechanisms SAMA CSF DE.CM-1 - Network monitoring
🟡 ISO 27001:2022
ISO 27001:2022 A.12.2.1 - Monitoring and logging ISO 27001:2022 A.12.6.1 - Management of technical vulnerabilities ISO 27001:2022 A.14.2.1 - Secure development policy
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 11.2 - Vulnerability scanning
📊 CVSS Score
6.3
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityL — Low / Local
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score6.3
CWECWE-74
EPSS0.43%
Exploit No
Patch ✗ No
Published 2026-06-05
Source Feed nvd
Views 1
🇸🇦 Saudi Risk Score
6.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-74
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.