Remote Command Injection in D-Link DWR-M961
D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 are vulnerable to unauthenticated command injection via the fota_url parameter.
What's new
D-Link DWR-M961 routers, specifically hardware version C1, contain a critical command injection vulnerability identified as CVE-2026-71944. The vulnerability exists within the firmware upgrade interface located at /boafrm/formLtefotaUpgradeQuectel. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request containing malicious commands in the fota_url parameter. Successful exploitation allows the attacker to execute arbitrary code with root privileges on the affected device, potentially leading to a complete compromise of the router. This vulnerability highlights the risks associated with improper input validation in router administrative interfaces. Defenders should prioritize patching, as this device class is a common target for botnet recruitment and persistent unauthorized access.
Impact
The vulnerability carries a CVSS 3.1 base score of 9.8, indicating high severity and ease of exploitation. An attacker who successfully triggers this vulnerability gains full administrative control over the DWR-M961 device. Potential impacts include device bricking, participation in DDoS botnets, man-in-the-middle attacks on local network traffic, and establishment of persistent backdoors within the organization's network perimeter.
Recommendation
Prioritize updating the firmware of all D-Link DWR-M961 (C1 hardware) devices to version 1.1.5_C1_202607071108 or later immediately. Ensure these devices are not exposed to the public internet by placing them behind a firewall or using a VPN for remote management.
Detection coverage 1
Detects CVE-2026-71944 Exploitation - Potential Command Injection in D-Link DWR-M961
criticalDetects potential command injection attempts targeting the FOTA upgrade interface of D-Link DWR-M961 devices by monitoring for shell metacharacters in the fota_url parameter.
Detection queries are available on the platform. Get full rules →