Executive brief
The D-Link DWR-M961 is an LTE router used for mobile broadband connectivity in enterprise and industrial networks. A critical command injection vulnerability in its web-management interface allows a remote attacker to execute arbitrary commands with root privileges, potentially giving complete control of the device and any networks it protects.
Technical details
Multiple command injection vulnerabilities exist in the web-management CGI components of the DWR-M961, affecting parameters in diagnostic functions (ping, traceroute, debug), FOTA upgrade handlers, SMS management, USSD setup, and other interfaces. The vulnerable endpoints include /boafrm/formPingDiagnosticRun, /boafrm/formTracerouteDiagnosticRun, /boafrm/formDebugDiagnosticRun, and others that fail to properly sanitize user input before passing it to system commands. Remote attackers can inject malicious shell commands (e.g., via the host field in ping diagnostics) to achieve arbitrary code execution with root privileges; no authentication is explicitly required based on the advisory. The vulnerabilities were resolved in firmware version 1.1.5_C1_202607071108 and later.
Affected products
- D-Link DWR-M961 1.1.2_C1_202602110044 (hardware revision C1)
Timeline
- 2026-08-08: disclosed: CVE-2026-71956 and related CVEs (15 total) disclosed
- 2026-07-07: patched: Resolved in firmware 1.1.5_C1_202607071108