Junglewise Threat Intelligence

CVE-2026-71945: D-Link DWR-M961 command injection in FOTA upgrade handler

CVE-2026-71945 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: D-Link DWR-M961. Vendors: D-Link.

Executive brief

The D-Link DWR-M961 is a 4G LTE router that manages firmware updates and system configuration through a web-based interface. A command injection vulnerability in the firmware upgrade handler allows a remote attacker to inject arbitrary system commands that execute with root privileges, enabling complete device takeover, data theft, or use as an attack pivot point.

Technical details

The vulnerability is a command injection flaw in the /boafrm/formLtefotaUpgradeFibocom web-management CGI handler. The fota_url parameter is not properly sanitized before being passed to a system command, allowing an attacker to inject shell metacharacters and arbitrary commands. The attack requires network access to the web interface (typically requiring authentication or device access) but yields command execution at root privilege level. This affects DWR-M961 hardware revision C1 running firmware versions before 1.1.5_C1_202607071108. The vulnerability was resolved in the patched firmware version.

Affected products

  • D-Link DWR-M961 Hardware revision C1, firmware before 1.1.5_C1_202607071108

Timeline

  • 2026-08-08: disclosed: CVE published by NVD
  • 2026-08-10: advisory: D-Link security advisory SAP10512 updated
  • 2026-07-07: patched: Firmware version 1.1.5_C1_202607071108 resolves vulnerability

References

Related threats