Junglewise Threat Intelligence

CVE-2026-71944: D-Link DWR-M961 command injection in FOTA upgrade handler

CVE-2026-71944 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: D-Link DWR-M961. Vendors: D-Link.

Executive brief

The D-Link DWR-M961 is a 4G LTE router used for mobile broadband connectivity in remote or underserved locations. A remote attacker can inject arbitrary system commands through the firmware-over-the-air upgrade interface, gaining root-level control over the device and its network traffic without authentication. This could lead to complete compromise of corporate or organizational networks that rely on the router.

Technical details

The vulnerability is a command injection flaw in the /boafrm/formLtefotaUpgradeQuectel web-management CGI endpoint, specifically in the fota_url parameter. The vulnerable component fails to properly sanitize user input before passing it to system command execution, allowing an attacker to inject shell metacharacters and execute arbitrary commands with root privileges. The attack requires network access to the web interface but does not require authentication. Remote attackers can exploit this to achieve unauthenticated remote code execution as root. D-Link resolved the issue in firmware version 1.1.5_C1_202607071108 and later.

Affected products

  • D-Link DWR-M961 hardware revision C1, firmware versions before 1.1.5_C1_202607071108

Timeline

  • 2026-08-08: disclosed
  • 2026-07-07: patched: firmware version 1.1.5_C1_202607071108

References

Related threats