Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide mobile broadband connectivity in small office and home environments. A command injection vulnerability in the device's web management interface allows remote attackers to execute arbitrary commands with root privileges, potentially compromising the router and all devices connected to it.
Technical details
This is a command injection vulnerability in the /boafrm/formIMEISetup interface of the D-Link DWR-M961 router (hardware revision C1). The IMEI_value parameter fails to properly sanitize user input before passing it to a system command, allowing an attacker to inject arbitrary shell metacharacters and execute commands with root privileges. The vulnerability is network-reachable via the device's web-management interface; no authentication is explicitly mentioned as a requirement. An attacker can achieve arbitrary code execution as root on the device. The vulnerability is resolved in firmware version 1.1.5_C1_202607071108 and later.
Affected products
- D-Link DWR-M961 hardware revision C1, firmware before 1.1.5_C1_202607071108
Timeline
- 2026-08-08: disclosed: CVE published on NVD
- 2026-07-07: patched: Firmware 1.1.5_C1_202607071108 released to address vulnerability
- 2026-08-10: advisory: D-Link security announcement SAP10512 updated