Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide internet connectivity in home and business networks. An unauthenticated remote attacker can inject arbitrary system commands through the device's web-based diagnostic interface, gaining complete control (root-level access) of the router. This allows attackers to modify network configurations, intercept traffic, install malware, or launch further attacks on connected networks.
Technical details
The vulnerability is a classic command injection flaw in the /boafrm/formTracerouteDiagnosticRun web CGI handler. Attacker-controlled input in the "host" and "ipVer" parameters is passed unsanitized to system shell commands, allowing injection of arbitrary shell metacharacters and commands. The vulnerability requires only network reachability to the device's web interface (typically port 80/443); no authentication is required. An attacker can execute arbitrary commands with root privileges by crafting a malicious HTTP request containing shell metacharacters in the affected parameters. D-Link resolved this issue in firmware version 1.1.5_C1_202607071108 and later.
Affected products
- D-Link DWR-M961 Hardware revision C1, firmware before 1.1.5_C1_202607071108
Timeline
- 2026-08-08: disclosed
- 2026-07-07: patched: Firmware version 1.1.5_C1_202607071108