CVE-2026-71951

D-Link · DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formIMEISetup interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.

Executive summary

The D-Link DWR-M961 router contains a critical command injection vulnerability that enables unauthenticated remote attackers to gain full root-level control over the device.

Vulnerability

This is an OS command injection flaw (CWE-78) located in the /boafrm/formIMEISetup interface. The application fails to properly sanitize input in the IMEI_value field, allowing an unauthenticated remote attacker to inject malicious system commands.

Business impact

A successful exploitation of this vulnerability results in full administrative control over the affected network device. This allows attackers to pivot into internal networks, intercept traffic, or deploy persistent malware. Given the CVSS score of 9.8, the risk to confidentiality, integrity, and availability is extreme, potentially leading to a complete compromise of the network perimeter.

Remediation

Immediate Action: Update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later immediately.

Proactive Monitoring: Monitor system logs for unusual process execution or unauthorized configuration changes initiated via the web management interface.

Compensating Controls: Restrict access to the router management interface to trusted internal IP addresses only, and employ a Web Application Firewall to filter malicious input strings.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability represents a critical risk to infrastructure security. Administrators must prioritize the application of the vendor-provided firmware update to eliminate the command injection vector, as failure to do so leaves the device susceptible to total unauthorized control.