CVE-2026-71948
D-Link · DWR-M961
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formDebugDiagnosticRun interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.
Executive summary
A critical command injection vulnerability in D-Link DWR-M961 routers allows remote attackers to achieve full system compromise with root-level access.
Vulnerability
This is an OS Command Injection vulnerability (CWE-78) occurring within the /boafrm/formDebugDiagnosticRun interface. The flaw permits an unauthenticated remote attacker to inject malicious inputs into the host field, which the system executes with root privileges.
Business impact
The CVSS score of 9.8 reflects the high severity of this vulnerability, as it allows for total control over the affected network device. Compromise of an edge router can lead to unauthorized network access, interception of traffic, and the potential for the device to be used as a pivot point for deeper lateral movement within the corporate environment.
Remediation
Immediate Action: Update the firmware of all affected D-Link DWR-M961 (Hardware C1) devices to version 1.1.5_C1_202607071108 or later immediately.
Proactive Monitoring: Monitor network traffic and system logs for unusual diagnostic requests or suspicious shell execution patterns directed at the device administration interface.
Compensating Controls: Restrict access to the device management interface to trusted internal IP addresses only, and ensure the device is not directly exposed to the public internet.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the critical nature of this vulnerability and the potential for complete device takeover, organizations must prioritize patching all affected routers. If immediate patching is not feasible, ensure the management interface is isolated from external networks to prevent remote exploitation.