Impact
A command injection flaw exists in the sub_419920 function of the /boafrm/formLtefotaUpgradeQuectel component within D-Link DWR‑M961 firmware 1.1.47. An attacker can manipulate the fota_url parameter to inject arbitrary operating system commands, which can be executed on the router. This vulnerability falls under CWE‑74 and CWE‑77. Because the injected commands run with the privileges of the underlying service, the attacker could potentially gain significant control over the device, such as modifying configuration, installing malware, or pivoting to other network assets.
Affected Systems
D-Link DWR‑M961 routers operating firmware version 1.1.47 are vulnerable. Device owners should verify if their equipment runs this firmware and observe whether the /boafrm/formLtefotaUpgradeQuectel endpoint is exposed to untrusted networks.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity, while the EPSS score of 2% indicates a low but non‑zero probability of exploitation. The vulnerability is remotely reachable through the formLtefotaUpgradeQuectel interface, and publicly documented exploits are available, meaning the risk is real but not widespread. The device is not listed in CISA’s KEV catalog, yet the existence of a command injection that can lead to arbitrary OS command execution warrants remediation.
OpenCVE Enrichment