CVE-2026-71944
D-Link · DWR-M961
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formLtefotaUpgradeQuectel interface allows unauthenticated remote attackers to execute arbitrary commands as root.
Executive summary
A critical command injection vulnerability in D-Link DWR-M961 routers allows remote, unauthenticated attackers to execute arbitrary code with root privileges.
Vulnerability
The vulnerability exists in the /boafrm/formLtefotaUpgradeQuectel interface, which fails to sanitize the fota_url parameter (CWE-78). This allows an unauthenticated remote attacker to inject malicious commands that are then executed by the system with root-level permissions.
Business impact
The CVSS score of 9.8 highlights the severity of this issue. Compromise of the DWR-M961 router provides an attacker with a foothold in the local network, potentially facilitating man-in-the-middle attacks, data theft, and long-term persistence within the enterprise environment.
Remediation
Immediate Action: Update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later to resolve the injection flaw.
Proactive Monitoring: Monitor network logs for unusual requests directed toward the FOTA (Firmware Over-The-Air) upgrade interface.
Compensating Controls: Use a network-level firewall or Access Control List (ACL) to restrict access to the device management interface to authorized management subnets only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
All organizations utilizing D-Link DWR-M961 hardware must prioritize upgrading to firmware version 1.1.5_C1_202607071108. The ease of remote execution without authentication makes this a critical risk that must be addressed immediately to maintain network security.