Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide mobile broadband connectivity to networks. A command injection vulnerability in the device's web management interface allows attackers to execute arbitrary system commands with root privileges, enabling complete device compromise and potential lateral attacks into connected networks.
Technical details
This is a command injection vulnerability (CWE-78) in the /boafrm/formDebugDiagnosticRun web management CGI endpoint. The vulnerability exists in the host input field of the debug diagnostic function, where user-supplied input is not properly sanitized before being passed to system command execution. An unauthenticated remote attacker on the network can send a crafted HTTP request with malicious commands embedded in the host parameter to achieve arbitrary command execution with root privileges. The vulnerability affects hardware revision C1 running firmware versions prior to 1.1.5_C1_202607071108, which contains the fix.
Affected products
- D-Link DWR-M961 hardware revision C1 running firmware before 1.1.5_C1_202607071108
Timeline
- 2026-08-08: disclosed: CVE-2026-71948 published
- 2026-07-07: patched: Fixed in firmware version 1.1.5_C1_202607071108