CVE-2026-71946

D-Link · DWR-M961

A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the host parameter in the ping interface.

Executive summary

D-Link DWR-M961 routers contain a critical command injection vulnerability that permits unauthenticated remote code execution with root privileges.

Vulnerability

This is a command injection flaw (CWE-78) within the /boafrm/formPingDiagnosticRun interface. An unauthenticated attacker can supply malicious input to the host field, resulting in the execution of arbitrary commands with root privileges on the underlying operating system.

Business impact

The severity of this issue is reflected in the 9.8 CVSS score, indicating a high potential for total system compromise. An attacker could leverage this access to intercept sensitive data, modify network configurations, or launch attacks against other devices within the local network environment.

Remediation

Immediate Action: Apply the vendor-supplied firmware update to version 1.1.5_C1_202607071108 or later.

Proactive Monitoring: Review system and firewall logs for anomalous activity involving diagnostic interface calls or unexpected shell command patterns.

Compensating Controls: Disable remote access to the diagnostic tools if possible, and ensure the router is protected by a strong firewall policy that limits access to the web management interface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a significant security risk to the integrity and confidentiality of the network. Administrators should prioritize applying the firmware update across all affected D-Link DWR-M961 units to mitigate the risk of remote command injection.