<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>DWR-M961 (Hardware Version C1, Software Version 1.1.2_C1_202602110044) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/dwr-m961-hardware-version-c1-software-version-1.1.2_c1_202602110044/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 08 Aug 2026 17:40:26 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/dwr-m961-hardware-version-c1-software-version-1.1.2_c1_202602110044/feed.xml" rel="self" type="application/rss+xml"/><item><title>Remote Command Injection in D-Link DWR-M961</title><link>https://feed.craftedsignal.io/briefs/2026-08-dlink-command-injection/</link><pubDate>Sat, 08 Aug 2026 17:40:26 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-dlink-command-injection/</guid><description>D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 are vulnerable to unauthenticated command injection via the fota_url parameter.</description><content:encoded><![CDATA[<p>D-Link DWR-M961 routers, specifically hardware version C1, contain a critical command injection vulnerability identified as CVE-2026-71944. The vulnerability exists within the firmware upgrade interface located at /boafrm/formLtefotaUpgradeQuectel. An unauthenticated remote attacker can exploit this flaw by sending a crafted HTTP request containing malicious commands in the fota_url parameter. Successful exploitation allows the attacker to execute arbitrary code with root privileges on the affected device, potentially leading to a complete compromise of the router. This vulnerability highlights the risks associated with improper input validation in router administrative interfaces. Defenders should prioritize patching, as this device class is a common target for botnet recruitment and persistent unauthorized access.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS 3.1 base score of 9.8, indicating high severity and ease of exploitation. An attacker who successfully triggers this vulnerability gains full administrative control over the DWR-M961 device. Potential impacts include device bricking, participation in DDoS botnets, man-in-the-middle attacks on local network traffic, and establishment of persistent backdoors within the organization's network perimeter.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize updating the firmware of all D-Link DWR-M961 (C1 hardware) devices to version 1.1.5_C1_202607071108 or later immediately. Ensure these devices are not exposed to the public internet by placing them behind a firewall or using a VPN for remote management.</p>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>vulnerability</category><category>remote-code-execution</category><category>network-security</category></item></channel></rss>