Executive brief
The D-Link DWR-M961 is a 4G LTE router used to provide internet connectivity to businesses and remote locations. A critical vulnerability in its web-management interface allows remote attackers to inject malicious commands that execute with root privileges, potentially compromising the entire device and any networks it protects.
Technical details
The vulnerability is a command injection flaw in the /boafrm/formWsc web-management CGI handler affecting hardware revision C1 running firmware 1.1.2_C1_202602110044. An attacker can inject arbitrary shell commands through multiple vulnerable parameters (localPin, targetAPSsid, peerPin, and peerRptPin) without authentication, resulting in unauthenticated remote code execution with root privileges. The vulnerability has been resolved in firmware version 1.1.5_C1_202607071108. This represents finding 12–14 from the original technical report grouped under a single CVE identifier.
Affected products
- D-Link DWR-M961 hardware revision C1 with firmware 1.1.2_C1_202602110044
Timeline
- 2026-08-08: disclosed: CVE-2026-71955 published
- 2026-08-10: advisory: D-Link security advisory SAP10512 last updated
- 2026-07-07: patched: Resolved in firmware 1.1.5_C1_202607071108