CVE-2026-71949
D-Link · DWR-M961
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formUSSDSetup interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.
Executive summary
A critical command injection vulnerability in D-Link DWR-M961 routers allows remote attackers to achieve full system compromise with root-level access.
Vulnerability
The /boafrm/formUSSDSetup interface fails to properly sanitize user input, leading to an OS Command Injection vulnerability (CWE-78). Remote unauthenticated attackers can supply malicious input via the ussdValue or selectMenuValue fields to gain root-level command execution.
Business impact
With a CVSS score of 9.8, this vulnerability poses a severe threat to organizational security. Successful exploitation grants an attacker administrative control over the router, facilitating data exfiltration, traffic redirection, or the permanent installation of persistent malware on the gateway device.
Remediation
Immediate Action: Apply the firmware update 1.1.5_C1_202607071108 or newer to all identified D-Link DWR-M961 units.
Proactive Monitoring: Review system logs for unexpected USSD-related configuration changes or anomalous process execution originating from the web management interface.
Compensating Controls: Employ firewall rules to block external access to the device management interface and consider disabling unused features if they cannot be patched immediately.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant risk to network integrity. Security teams should treat this update with high urgency and ensure all hardware C1 devices are brought to the patched firmware version as soon as possible.