Junglewise Threat Intelligence

CVE-2026-71955: D-Link DWR-M961 command injection in formWsc

CVE-2026-71955 · Severity: critical · CVSS 9.8 · Published 2026-08-08

Technologies: D-Link DWR-M961. Vendors: D-Link.

Executive brief

The D-Link DWR-M961 is a 4G LTE router used to provide internet connectivity to businesses and remote locations. A critical vulnerability in its web-management interface allows remote attackers to inject malicious commands that execute with root privileges, potentially compromising the entire device and any networks it protects.

Technical details

The vulnerability is a command injection flaw in the /boafrm/formWsc web-management CGI handler affecting hardware revision C1 running firmware 1.1.2_C1_202602110044. An attacker can inject arbitrary shell commands through multiple vulnerable parameters (localPin, targetAPSsid, peerPin, and peerRptPin) without authentication, resulting in unauthenticated remote code execution with root privileges. The vulnerability has been resolved in firmware version 1.1.5_C1_202607071108. This represents finding 12–14 from the original technical report grouped under a single CVE identifier.

Affected products

  • D-Link DWR-M961 hardware revision C1 with firmware 1.1.2_C1_202602110044

Timeline

  • 2026-08-08: disclosed: CVE-2026-71955 published
  • 2026-08-10: advisory: D-Link security advisory SAP10512 last updated
  • 2026-07-07: patched: Resolved in firmware 1.1.5_C1_202607071108

References

Related threats