Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide internet connectivity in homes and small businesses. A remote attacker can inject malicious system commands through the device's web management interface, gaining control of the router with full administrative privileges. This could allow an attacker to steal network traffic, intercept data, or use the device as a foothold to attack other networks.
Technical details
The vulnerability is a command injection flaw in the /boafrm/formPingDiagnosticRun web CGI interface of the D-Link DWR-M961. The vulnerable "host" parameter fails to properly sanitize user input before passing it to a system command, allowing an attacker to inject arbitrary shell commands. The vulnerability requires network access to the web management interface (typically port 80 or 8080) but no authentication is explicitly mentioned as a prerequisite in the advisory. Successful exploitation results in arbitrary command execution with root-level privileges. The vulnerability is resolved in firmware version 1.1.5_C1_202607071108 and later.
Affected products
- D-Link DWR-M961 Hardware version C1, firmware before 1.1.5_C1_202607071108
Timeline
- 2026-08-08: disclosed: CVE-2026-71946 published on NVD
- 2026-08-10: patched: D-Link firmware 1.1.5_C1_202607071108 resolves the vulnerability
- 2026-08-10: advisory: D-Link security announcement SAP10512 updated