CVE-2026-71955

D-Link · DWR-M961

D-Link DWR-M961 routers are vulnerable to command injection in the /boafrm/formWsc interface, enabling unauthenticated remote attackers to execute arbitrary commands as root.

Executive summary

A critical command injection vulnerability in D-Link DWR-M961 routers enables unauthenticated attackers to execute arbitrary commands with root privileges.

Vulnerability

This vulnerability arises from improper neutralization of special elements in the localPin, targetAPSsid, peerPin, and peerRptPin fields within the /boafrm/formWsc interface. It allows unauthenticated remote attackers to execute system commands with root-level permissions.

Business impact

Exploitation of this vulnerability allows full control over the affected hardware, which may result in data exfiltration, the installation of persistent backdoors, or the redirection of network traffic. With a CVSS score of 9.8, this represents a critical risk that could lead to widespread organizational compromise.

Remediation

Immediate Action: Apply the vendor firmware update to version 1.1.5_C1_202607071108 or later to resolve the vulnerability.

Proactive Monitoring: Review system logs for anomalous interactions with the /boafrm/formWsc interface or unexpected system command activity.

Compensating Controls: Ensure that administrative interfaces are not reachable from the public internet and employ firewall rules to limit access to trusted IP ranges.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations must move quickly to update the firmware on all D-Link DWR-M961 routers. Failure to patch these devices leaves the network vulnerable to total compromise by remote attackers.