Impact
The vulnerability is a command injection flaw in the /boafrm/formLtefotaUpgradeQuectel interface of D-Link DWR‑M961 routers. An attacker can supply a crafted fota_url parameter containing arbitrary shell commands. These commands are executed with root privilege on the device, allowing full compromise of the router. The flaw is a classic command injection, CWE‑78.
Affected Systems
Affected devices are D‑Link DWR‑M961 routers with hardware version C1 and firmware revisions earlier than 1.1.5_C1_202607071108. No other hardware or firmware versions are known to be impacted.
Risk and Exploitability
The CVSS base score of 9.3 indicates critical severity. Because the EPSS score is not available, the exploitation probability cannot be quantified, but the lack of an existing KEV listing does not diminish the risk posed by the high authority of the exploit. Attackers can trigger the vulnerability by sending a specially crafted HTTP request to the vulnerable endpoint from any network location that can reach the router’s HTTP server, so remote execution is feasible without authentication.
OpenCVE Enrichment