Junglewise Threat Intelligence

CVE-2026-71950: D-Link DWR-M961 command injection in SMS management

CVE-2026-71950 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: D-Link DWR-M961. Vendors: D-Link.

Executive brief

The D-Link DWR-M961 is a 4G LTE router used to provide mobile broadband connectivity for remote locations and businesses. A command injection vulnerability in the web-based management interface allows an attacker to execute arbitrary system commands with root privileges by sending a specially crafted request to the SMS management function. This could enable an attacker to completely compromise the router, steal user data, redirect traffic, or use the device as a pivot point to attack other networks.

Technical details

The vulnerability is a command injection flaw in the /boafrm/formSmsManage web-management CGI interface, affecting the action_value parameter when action_id is set to "delete" or "readMsg". The vulnerable component fails to properly sanitize user-supplied input before passing it to a system shell command. A remote attacker can inject malicious shell metacharacters and commands into the action_value field, resulting in arbitrary command execution with root privileges. No authentication is explicitly stated as a requirement. The vulnerability was resolved in firmware version 1.1.5_C1_202607071108.

Affected products

  • D-Link DWR-M961 hardware version C1, firmware before 1.1.5_C1_202607071108

Timeline

  • 2026-05-28: other: Vulnerability report received by D-Link
  • 2026-08-03: disclosed: Security advisory SAP10512 published
  • 2026-08-08: advisory: CVE-2026-71950 published

References

Related threats