CVE-2026-71950
D-Link · DWR-M961
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formSmsManage interface allows remote unauthenticated attackers to execute arbitrary system commands with root privileges.
Executive summary
A critical command injection vulnerability in D-Link DWR-M961 routers allows remote attackers to achieve full system compromise with root-level access.
Vulnerability
This vulnerability is an OS Command Injection (CWE-78) located in the /boafrm/formSmsManage interface. Attackers can leverage the action_value field to inject arbitrary commands, executing them with root privileges without needing to authenticate.
Business impact
The CVSS score of 9.8 highlights the critical nature of this flaw, which allows for total compromise of the router. Potential impacts include unauthorized access to internal network segments, surveillance of network communications, and the potential for a complete breakdown of perimeter security.
Remediation
Immediate Action: Update all D-Link DWR-M961 (Hardware C1) devices to firmware version 1.1.5_C1_202607071108 or later.
Proactive Monitoring: Inspect device logs for suspicious SMS management actions or unexpected command-line activity associated with the web service.
Compensating Controls: Implement strict access control lists to prevent external entities from reaching the router management interface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given that this is one of multiple critical injection vulnerabilities identified in the same device, it is imperative to apply the provided firmware update immediately. Failure to patch leaves the internal network exposed to full remote control by unauthorized actors.