CVE-2026-71954
D-Link · DWR-M961
D-Link DWR-M961 routers contain a command injection vulnerability in the L2TPv3 configuration interface allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.
Executive summary
An unauthenticated remote command injection vulnerability in D-Link DWR-M961 routers allows full system compromise via the L2TPv3 configuration interface.
Vulnerability
This is an OS command injection vulnerability (CWE-78) occurring within the /boafrm/formL2tpv3ConfigSetup interface. An unauthenticated attacker can supply malicious input to the tunnelid and sessionid parameters to execute commands with root-level privileges.
Business impact
The CVSS score of 9.8 reflects the critical severity of this flaw, as it allows complete takeover of the affected device without requiring authentication. Compromise of network infrastructure devices can lead to unauthorized traffic interception, lateral movement into internal segments, and persistent denial of service, posing a severe risk to organizational network integrity.
Remediation
Immediate Action: Update the D-Link DWR-M961 firmware to version 1.1.5_C1_202607071108 or later immediately.
Proactive Monitoring: Monitor device logs for unusual activity, specifically looking for attempts to access the L2TPv3 configuration interface from unauthorized IP addresses.
Compensating Controls: Restrict access to the router management interface to trusted administrative IP addresses only, and employ a network firewall to block inbound access to the web management interface from untrusted networks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical nature of this vulnerability and the potential for full system compromise, administrators must prioritize the firmware update as an urgent task. If patching is not immediately feasible, ensure that the device management interface is not exposed to the public internet to mitigate the risk of remote exploitation.