Junglewise Threat Intelligence

CVE-2026-71949: D-Link DWR-M961 command injection in USSD setup

CVE-2026-71949 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: D-Link DWR-M961. Vendors: D-Link.

Executive brief

The D-Link DWR-M961 is a 4G LTE router used to provide broadband connectivity for offices and remote locations. A remote attacker can inject malicious commands into the device's web-based management interface without authentication, gaining complete control of the router with root privileges. This allows attackers to intercept network traffic, compromise connected devices, disrupt service, or launch attacks on downstream networks.

Technical details

This is a command-injection vulnerability in the /boafrm/formUSSDSetup CGI handler on D-Link DWR-M961 hardware revision C1 devices. The vulnerability exists in two operating modes: the ussdValue field when ussdStatusInput=ussd and the selectMenuValue field when ussdStatusInput=menu. Both fields fail to properly sanitize user input before passing it to shell execution, allowing an attacker to inject arbitrary commands. The vulnerability is reachable over the network via the device's web-management interface; no authentication is required. Successful exploitation results in command execution with root privileges. The issue is resolved in firmware version 1.1.5_C1_202607071108.

Affected products

  • D-Link DWR-M961 hardware revision C1, firmware before 1.1.5_C1_202607071108

Timeline

  • 2026-08-08: disclosed
  • 2026-07-07: patched: Firmware 1.1.5_C1_202607071108 resolves the vulnerability

References

Related threats