{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/dwr-m961-hardware-version-c1-software-version-1.1.2_c1_202602110044/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-71944"},{"cvss":9.8,"id":"CVE-2026-71945"},{"cvss":9.8,"id":"CVE-2026-71946"},{"cvss":9.8,"id":"CVE-2026-71947"},{"cvss":9.8,"id":"CVE-2026-71948"},{"cvss":9.8,"id":"CVE-2026-71949"},{"cvss":9.8,"id":"CVE-2026-71950"},{"cvss":9.8,"id":"CVE-2026-71951"},{"cvss":9.8,"id":"CVE-2026-71952"},{"cvss":9.8,"id":"CVE-2026-71954"},{"cvss":9.8,"id":"CVE-2026-71953"},{"cvss":9.8,"id":"CVE-2026-71955"},{"cvss":9.8,"id":"CVE-2026-71958"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DWR-M961","DWR-M961 (\u003c 1.1.5_C1_202607071108)","DWR-M961 (version 1.1.2_C1_202602110044)","DWR-M961 (hardware version C1, software version 1.1.2_C1_202602110044)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","remote-code-execution","network-security"],"_cs_type":"advisory","_cs_vendors":["D-Link"],"content_html":"\u003cp\u003eD-Link DWR-M961 routers, specifically hardware version C1, contain a critical command injection vulnerability identified as CVE-2026-71944. The vulnerability exists within the firmware upgrade interface located at /boafrm/formLtefotaUpgradeQuectel. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request containing malicious commands in the fota_url parameter. Successful exploitation allows the attacker to execute arbitrary code with root privileges on the affected device, potentially leading to a complete compromise of the router. This vulnerability highlights the risks associated with improper input validation in router administrative interfaces. Defenders should prioritize patching, as this device class is a common target for botnet recruitment and persistent unauthorized access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability carries a CVSS 3.1 base score of 9.8, indicating high severity and ease of exploitation. An attacker who successfully triggers this vulnerability gains full administrative control over the DWR-M961 device. Potential impacts include device bricking, participation in DDoS botnets, man-in-the-middle attacks on local network traffic, and establishment of persistent backdoors within the organization's network perimeter.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating the firmware of all D-Link DWR-M961 (C1 hardware) devices to version 1.1.5_C1_202607071108 or later immediately. Ensure these devices are not exposed to the public internet by placing them behind a firewall or using a VPN for remote management.\u003c/p\u003e\n","date_modified":"2026-08-08T19:41:28Z","date_published":"2026-08-08T17:40:26Z","id":"https://feed.craftedsignal.io/briefs/2026-08-dlink-command-injection/","summary":"D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 are vulnerable to unauthenticated command injection via the fota_url parameter.","title":"Remote Command Injection in D-Link DWR-M961","url":"https://feed.craftedsignal.io/briefs/2026-08-dlink-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - DWR-M961 (Hardware Version C1, Software Version 1.1.2_C1_202602110044)","version":"https://jsonfeed.org/version/1.1"}