Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide internet connectivity in residential and business environments. A flaw in its web management interface allows a remote attacker to inject malicious commands through the PIN management function, leading to complete compromise of the device with root-level access. This could enable attackers to intercept network traffic, steal connected devices' data, or use the router as a pivot point for broader network attacks.
Technical details
The vulnerability is a command injection flaw in the /boafrm/formPinManageSetup endpoint of the device's web-management CGI component. The oldPin parameter fails to properly sanitize user input, allowing an attacker to inject arbitrary shell commands that execute with root privileges. The attack is network-accessible and requires no prior authentication. An attacker can achieve remote code execution and complete device compromise by crafting a specially-crafted request with malicious payload in the oldPin field. The vulnerability was resolved in firmware version 1.1.5_C1_202607071108.
Affected products
- D-Link DWR-M961 Hardware revision C1 with firmware before 1.1.5_C1_202607071108
Timeline
- 2026-08-08: disclosed
- 2026-07-07: patched: Firmware version 1.1.5_C1_202607071108 resolves the vulnerability