Skip to content
Threat Feed
critical advisory

Remote Command Injection in D-Link DWR-M961

D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 are vulnerable to unauthenticated command injection via the fota_url parameter.

What's new

  • 1. added CVE-2026-71958 Aug 8, 19:41 via nvd
  • 2. new product Aug 8, 19:41 via nvd
  • 3. added CVE-2026-71953 +1 Aug 8, 19:40 via nvd
  • 4. added CVE-2026-71952, CVE-2026-71954 Aug 8, 17:43 via nvd, source

D-Link DWR-M961 routers, specifically hardware version C1, contain a critical command injection vulnerability identified as CVE-2026-71944. The vulnerability exists within the firmware upgrade interface located at /boafrm/formLtefotaUpgradeQuectel. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request containing malicious commands in the fota_url parameter. Successful exploitation allows the attacker to execute arbitrary code with root privileges on the affected device, potentially leading to a complete compromise of the router. This vulnerability highlights the risks associated with improper input validation in router administrative interfaces. Defenders should prioritize patching, as this device class is a common target for botnet recruitment and persistent unauthorized access.

Impact

The vulnerability carries a CVSS 3.1 base score of 9.8, indicating high severity and ease of exploitation. An attacker who successfully triggers this vulnerability gains full administrative control over the DWR-M961 device. Potential impacts include device bricking, participation in DDoS botnets, man-in-the-middle attacks on local network traffic, and establishment of persistent backdoors within the organization's network perimeter.

Recommendation

Prioritize updating the firmware of all D-Link DWR-M961 (C1 hardware) devices to version 1.1.5_C1_202607071108 or later immediately. Ensure these devices are not exposed to the public internet by placing them behind a firewall or using a VPN for remote management.

Detection coverage 1

Detects CVE-2026-71944 Exploitation - Potential Command Injection in D-Link DWR-M961

critical

Detects potential command injection attempts targeting the FOTA upgrade interface of D-Link DWR-M961 devices by monitoring for shell metacharacters in the fota_url parameter.

sigma tactics: initial_access techniques: T1190 sources: webserver

Detection queries are available on the platform. Get full rules →