CVE-2026-71945
D-Link · DWR-M961
A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the fota_url parameter.
Executive summary
D-Link DWR-M961 routers are vulnerable to unauthenticated remote command injection, posing a critical risk of full system compromise.
Vulnerability
This is a command injection flaw (CWE-78) located in the /boafrm/formLtefotaUpgradeFibocom interface. The vulnerability allows an unauthenticated remote attacker to inject malicious commands into the fota_url field, which are then executed by the system with root-level privileges.
Business impact
Successful exploitation of this vulnerability grants an attacker complete control over the affected router. Given the CVSS score of 9.8, this is a critical risk that could lead to unauthorized access to internal network traffic, credential theft, or the use of the device as a pivot point for further attacks on the internal network.
Remediation
Immediate Action: Update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later immediately.
Proactive Monitoring: Monitor network logs for unusual outbound traffic or requests directed at the /boafrm/ directory, as these may indicate attempted exploitation.
Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and employ a Web Application Firewall to block suspicious input patterns in URL parameters.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for total device takeover, all affected hardware must be updated to the patched firmware version as a priority. If immediate patching is not feasible, ensure the device management interface is not exposed to the public internet.