Description
A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Published: 2026-01-29
Score: 5.3 Medium
EPSS: 1.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A command injection flaw exists in the sub_419920 function of the /boafrm/formLtefotaUpgradeQuectel component within D-Link DWR‑M961 firmware 1.1.47. An attacker can manipulate the fota_url parameter to inject arbitrary operating system commands, which can be executed on the router. This vulnerability falls under CWE‑74 and CWE‑77. Because the injected commands run with the privileges of the underlying service, the attacker could potentially gain significant control over the device, such as modifying configuration, installing malware, or pivoting to other network assets.

Affected Systems

D-Link DWR‑M961 routers operating firmware version 1.1.47 are vulnerable. Device owners should verify if their equipment runs this firmware and observe whether the /boafrm/formLtefotaUpgradeQuectel endpoint is exposed to untrusted networks.

Risk and Exploitability

The CVSS score of 5.3 reflects moderate severity, while the EPSS score of 2% indicates a low but non‑zero probability of exploitation. The vulnerability is remotely reachable through the formLtefotaUpgradeQuectel interface, and publicly documented exploits are available, meaning the risk is real but not widespread. The device is not listed in CISA’s KEV catalog, yet the existence of a command injection that can lead to arbitrary OS command execution warrants remediation.

Generated by OpenCVE AI on June 18, 2026 at 11:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any vendor-released firmware update that addresses the command injection flaw.
  • If an immediate firmware update is not possible, restrict external access to the /boafrm/formLtefotaUpgradeQuectel endpoint by configuring network firewalls or disabling remote firmware upgrade functionality.
  • As a temporary safeguard, remove or disable the web interface that processes the fota_url parameter if it is not essential for business operations.

Generated by OpenCVE AI on June 18, 2026 at 11:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 10 Feb 2026 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dwr-m961
Dlink dwr-m961 Firmware
CPEs cpe:2.3:h:dlink:dwr-m961:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m961_firmware:1.1.47:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dwr-m961
Dlink dwr-m961 Firmware

Fri, 30 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Thu, 29 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 29 Jan 2026 16:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in D-Link DWR-M961 1.1.47. This vulnerability affects the function sub_419920 of the file /boafrm/formLtefotaUpgradeQuectel. This manipulation of the argument fota_url causes command injection. The attack is possible to be carried out remotely. The exploit has been published and may be used.
Title D-Link DWR-M961 formLtefotaUpgradeQuectel sub_419920 command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

D-link Dwr-m961
Dlink Dwr-m961 Dwr-m961 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:05:29.768Z

Reserved: 2026-01-29T08:34:29.251Z

Link: CVE-2026-1596

cve-icon Vulnrichment

Updated: 2026-01-29T21:29:42.639Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-29T16:16:14.990

Modified: 2026-06-17T10:16:08.207

Link: CVE-2026-1596

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-18T11:30:04Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')