Executive brief
The D-Link DWR-M961 is a 4G/LTE router used to provide broadband connectivity in remote or mobile locations. A command injection vulnerability in its web management interface allows attackers to inject malicious commands through the L2TPv3 configuration fields, leading to remote code execution with root privileges on the device. An attacker can take complete control of the router, intercept traffic, or use it as a pivot point into downstream networks.
Technical details
The vulnerability is a command injection flaw in the /boafrm/formL2tpv3ConfigSetup endpoint of the D-Link DWR-M961 web-management CGI. The tunnelid and sessionid input parameters are not properly sanitized before being passed to shell commands, allowing an unauthenticated or low-privilege attacker to inject arbitrary shell metacharacters. No authentication is required to access the vulnerable endpoint. Successful exploitation results in command execution with root privileges. The vulnerability was resolved in firmware version 1.1.5_C1_202607071108 and later.
Affected products
- D-Link DWR-M961 hardware version C1 with firmware before 1.1.5_C1_202607071108
Timeline
- 2026-08-08: disclosed: CVE published on NVD
- 2026-07-07: patched: Patched in firmware 1.1.5_C1_202607071108