CVE-2026-71953

D-Link · DWR-M961

A command injection vulnerability in the D-Link DWR-M961 /boafrm/formNtp interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.

Executive summary

The D-Link DWR-M961 router contains a critical command injection vulnerability that allows unauthenticated remote attackers to gain complete control over the device at the root level.

Vulnerability

This is an OS command injection flaw (CWE-78) affecting the /boafrm/formNtp interface. The vulnerability arises from inadequate sanitization of the ntpServerIp1 field, enabling unauthenticated remote attackers to execute arbitrary commands on the host system.

Business impact

Exploitation of this vulnerability grants the attacker full root access to the affected hardware. This compromises the entire device, allowing for unauthorized network access, data theft, and potential lateral movement into the protected network segments. The CVSS score of 9.8 underscores the critical nature of this vulnerability and the urgent need for mitigation.

Remediation

Immediate Action: Upgrade the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later to resolve the underlying command injection flaw.

Proactive Monitoring: Monitor network traffic and device logs for suspicious activity, particularly any attempts to reach the NTP configuration interface.

Compensating Controls: Implement firewall rules to block traffic to administrative ports from untrusted networks, and utilize network segmentation to limit the blast radius of a potential compromise.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Administrators must treat this vulnerability with the highest priority. Applying the provided firmware update is the only effective way to remediate this critical security risk and prevent potential exploitation by malicious actors.