CVE-2026-71947
D-Link · DWR-M961
A command injection vulnerability in the D-Link DWR-M961 router allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the traceroute interface.
Executive summary
D-Link DWR-M961 routers are susceptible to unauthenticated remote command injection, which can lead to complete system compromise.
Vulnerability
This is a command injection flaw (CWE-78) located in the /boafrm/formTracerouteDiagnosticRun interface. An unauthenticated attacker can inject arbitrary commands into the host and ipVer fields, leading to command execution with root-level privileges.
Business impact
With a CVSS score of 9.8, this vulnerability poses a critical threat to the business, as an attacker could gain full control over the router. This could result in unauthorized network interception, data exfiltration, or the establishment of a persistent foothold within the enterprise network.
Remediation
Immediate Action: Update the affected D-Link DWR-M961 devices to firmware version 1.1.5_C1_202607071108 or later.
Proactive Monitoring: Inspect traffic logs for suspicious strings or characters commonly used in command injection attacks directed at diagnostic endpoints.
Compensating Controls: Restrict access to the web administration panel to trusted management subnets and implement network-level egress filtering to prevent unauthorized callbacks from compromised devices.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This security flaw must be addressed immediately to prevent potential exploitation. Organizations should ensure that all routers are patched to the specified firmware version to eliminate the risk posed by this command injection vulnerability.