Junglewise Threat Intelligence

CVE-2026-71953: D-Link DWR-M961 command injection in NTP interface

CVE-2026-71953 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: D-Link DWR-M961. Vendors: D-Link.

Executive brief

The D-Link DWR-M961 is a 4G LTE router used to provide internet connectivity for homes and small businesses. A command injection flaw in the network time protocol (NTP) configuration interface allows a remote attacker to inject malicious commands that execute with root privileges, potentially giving an attacker complete control over the device and any networks it protects.

Technical details

A command injection vulnerability exists in the /boafrm/formNtp web-management CGI interface of the DWR-M961 hardware revision C1. The vulnerability is present in the ntpServerIp1 parameter, which does not properly sanitize user input before passing it to system commands. An unauthenticated remote attacker can craft a malicious HTTP request with injected shell commands in the ntpServerIp1 field to achieve arbitrary command execution with root privileges. The vulnerability was resolved in firmware version 1.1.5_C1_202607071108 and later.

Affected products

  • D-Link DWR-M961 Hardware revision C1 with firmware before 1.1.5_C1_202607071108

Timeline

  • 2026-08-08: disclosed
  • 2026-07-07: patched: Firmware version 1.1.5_C1_202607071108

References

Related threats