Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide broadband connectivity for offices and remote locations. A remote attacker can inject malicious commands into the device's web-based management interface without authentication, gaining complete control of the router with root privileges. This allows attackers to intercept network traffic, compromise connected devices, disrupt service, or launch attacks on downstream networks.
Technical details
This is a command-injection vulnerability in the /boafrm/formUSSDSetup CGI handler on D-Link DWR-M961 hardware revision C1 devices. The vulnerability exists in two operating modes: the ussdValue field when ussdStatusInput=ussd and the selectMenuValue field when ussdStatusInput=menu. Both fields fail to properly sanitize user input before passing it to shell execution, allowing an attacker to inject arbitrary commands. The vulnerability is reachable over the network via the device's web-management interface; no authentication is required. Successful exploitation results in command execution with root privileges. The issue is resolved in firmware version 1.1.5_C1_202607071108.
Affected products
- D-Link DWR-M961 hardware revision C1, firmware before 1.1.5_C1_202607071108
Timeline
- 2026-08-08: disclosed
- 2026-07-07: patched: Firmware 1.1.5_C1_202607071108 resolves the vulnerability