CVE-2026-71956

D-Link · DWR-M961

D-Link DWR-M961 routers contain a command injection vulnerability in the app.cgi interface, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges.

Executive summary

A critical command injection vulnerability in D-Link DWR-M961 routers allows unauthenticated attackers to achieve full system compromise with root privileges.

Vulnerability

This vulnerability involves improper neutralization of special elements used in an OS command within the netDig.ping.dst parameter of the app.cgi interface. It permits unauthenticated remote attackers to inject and execute arbitrary system commands.

Business impact

Successful exploitation grants an attacker root access to the affected router, which can lead to complete loss of network control, interception of traffic, and the potential for lateral movement into the internal network. Given the CVSS score of 9.8, this vulnerability represents a severe threat to business continuity and data confidentiality.

Remediation

Immediate Action: Update the D-Link DWR-M961 device firmware to version 1.1.5_C1_202607071108 or later immediately.

Proactive Monitoring: Monitor device logs for unusual process execution or attempts to access the app.cgi interface with malformed parameters.

Compensating Controls: Restrict management access to the router via the local network only and disable WAN-side administrative access to minimize exposure to external actors.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The severity of this issue necessitates immediate patching. Administrators should prioritize updating all affected D-Link DWR-M961 units to the latest firmware version to mitigate the risk of remote code execution.