CVE-2026-71952

D-Link · DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formPinManageSetup interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.

Executive summary

The D-Link DWR-M961 router is susceptible to a critical command injection vulnerability that permits unauthenticated remote attackers to execute arbitrary code with root-level permissions.

Vulnerability

This is an OS command injection vulnerability (CWE-78) within the /boafrm/formPinManageSetup interface. Insufficient input validation on the oldPIn field allows an unauthenticated remote attacker to inject and execute system commands.

Business impact

Successful exploitation allows an attacker to achieve full system compromise, providing them with root access to the underlying operating system. This could lead to data exfiltration, network traffic interception, or the use of the device as a persistent staging point for further attacks on the internal network. The high CVSS score of 9.8 reflects the ease of exploitation and the severity of the impact.

Remediation

Immediate Action: Apply the vendor-supplied firmware update to version 1.1.5_C1_202607071108 or newer as soon as possible.

Proactive Monitoring: Review device logs for unexpected command executions or attempts to access administrative management endpoints from external sources.

Compensating Controls: Disable remote management access to the device and ensure it is only accessible via a secure, isolated management VLAN or VPN.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical nature of this security flaw, immediate remediation is required. Security teams should ensure all affected D-Link DWR-M961 devices are patched to the latest firmware version to mitigate the risk of remote command execution.