Junglewise Threat Intelligence

CVE-2026-71952: D-Link DWR-M961 command injection in PIN management

CVE-2026-71952 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: D-Link DWR-M961. Vendors: D-Link.

Executive brief

The D-Link DWR-M961 is a 4G LTE router used to provide internet connectivity in residential and business environments. A flaw in its web management interface allows a remote attacker to inject malicious commands through the PIN management function, leading to complete compromise of the device with root-level access. This could enable attackers to intercept network traffic, steal connected devices' data, or use the router as a pivot point for broader network attacks.

Technical details

The vulnerability is a command injection flaw in the /boafrm/formPinManageSetup endpoint of the device's web-management CGI component. The oldPin parameter fails to properly sanitize user input, allowing an attacker to inject arbitrary shell commands that execute with root privileges. The attack is network-accessible and requires no prior authentication. An attacker can achieve remote code execution and complete device compromise by crafting a specially-crafted request with malicious payload in the oldPin field. The vulnerability was resolved in firmware version 1.1.5_C1_202607071108.

Affected products

  • D-Link DWR-M961 Hardware revision C1 with firmware before 1.1.5_C1_202607071108

Timeline

  • 2026-08-08: disclosed
  • 2026-07-07: patched: Firmware version 1.1.5_C1_202607071108 resolves the vulnerability

References

Related threats