Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide mobile broadband connectivity for remote locations and businesses. A command injection vulnerability in the web-based management interface allows an attacker to execute arbitrary system commands with root privileges by sending a specially crafted request to the SMS management function. This could enable an attacker to completely compromise the router, steal user data, redirect traffic, or use the device as a pivot point to attack other networks.
Technical details
The vulnerability is a command injection flaw in the /boafrm/formSmsManage web-management CGI interface, affecting the action_value parameter when action_id is set to "delete" or "readMsg". The vulnerable component fails to properly sanitize user-supplied input before passing it to a system shell command. A remote attacker can inject malicious shell metacharacters and commands into the action_value field, resulting in arbitrary command execution with root privileges. No authentication is explicitly stated as a requirement. The vulnerability was resolved in firmware version 1.1.5_C1_202607071108.
Affected products
- D-Link DWR-M961 hardware version C1, firmware before 1.1.5_C1_202607071108
Timeline
- 2026-05-28: other: Vulnerability report received by D-Link
- 2026-08-03: disclosed: Security advisory SAP10512 published
- 2026-08-08: advisory: CVE-2026-71950 published