CVE-2026-71953
D-Link · DWR-M961
A command injection vulnerability in the D-Link DWR-M961 /boafrm/formNtp interface allows unauthenticated remote attackers to execute arbitrary commands with root privileges.
Executive summary
The D-Link DWR-M961 router contains a critical command injection vulnerability that allows unauthenticated remote attackers to gain complete control over the device at the root level.
Vulnerability
This is an OS command injection flaw (CWE-78) affecting the /boafrm/formNtp interface. The vulnerability arises from inadequate sanitization of the ntpServerIp1 field, enabling unauthenticated remote attackers to execute arbitrary commands on the host system.
Business impact
Exploitation of this vulnerability grants the attacker full root access to the affected hardware. This compromises the entire device, allowing for unauthorized network access, data theft, and potential lateral movement into the protected network segments. The CVSS score of 9.8 underscores the critical nature of this vulnerability and the urgent need for mitigation.
Remediation
Immediate Action: Upgrade the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later to resolve the underlying command injection flaw.
Proactive Monitoring: Monitor network traffic and device logs for suspicious activity, particularly any attempts to reach the NTP configuration interface.
Compensating Controls: Implement firewall rules to block traffic to administrative ports from untrusted networks, and utilize network segmentation to limit the blast radius of a potential compromise.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Administrators must treat this vulnerability with the highest priority. Applying the provided firmware update is the only effective way to remediate this critical security risk and prevent potential exploitation by malicious actors.