Impact
The firmware of D-Link DWR‑M961 routers prior to version 1.1.5_C1_202607071108 contains a command injection flaw in the /boafrm/formLtefotaUpgradeFibocom endpoint. An attacker can supply arbitrary commands through the fota_url field, triggering execution with root privileges on the device. This flaw allows full compromise of the router, exposing the network and potentially providing a foothold for further attacks.
Affected Systems
D-Link DWR‑M961 4G AC1200 LTE routers with hardware version C1 running firmware older than 1.1.5_C1_202607071108.
Risk and Exploitability
The CVSS score of 9.3 underscores a critical severity. Although EPSS data is not published, the lack of a KEV listing does not reduce the urgency. The flaw can be exercised remotely by sending a crafted request to the vulnerable web interface; no special authentication is required per the description, so attackers can obtain root privilege directly. The impact spans confidentiality, integrity, and availability of the device and the network it supports.
OpenCVE Enrichment