CVE-2026-71945

D-Link · DWR-M961

A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the fota_url parameter.

Executive summary

D-Link DWR-M961 routers are vulnerable to unauthenticated remote command injection, posing a critical risk of full system compromise.

Vulnerability

This is a command injection flaw (CWE-78) located in the /boafrm/formLtefotaUpgradeFibocom interface. The vulnerability allows an unauthenticated remote attacker to inject malicious commands into the fota_url field, which are then executed by the system with root-level privileges.

Business impact

Successful exploitation of this vulnerability grants an attacker complete control over the affected router. Given the CVSS score of 9.8, this is a critical risk that could lead to unauthorized access to internal network traffic, credential theft, or the use of the device as a pivot point for further attacks on the internal network.

Remediation

Immediate Action: Update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later immediately.

Proactive Monitoring: Monitor network logs for unusual outbound traffic or requests directed at the /boafrm/ directory, as these may indicate attempted exploitation.

Compensating Controls: Restrict access to the device management interface to trusted administrative IP addresses only, and employ a Web Application Firewall to block suspicious input patterns in URL parameters.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for total device takeover, all affected hardware must be updated to the patched firmware version as a priority. If immediate patching is not feasible, ensure the device management interface is not exposed to the public internet.