Description
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The firmware of D-Link DWR‑M961 routers prior to version 1.1.5_C1_202607071108 contains a command injection flaw in the /boafrm/formLtefotaUpgradeFibocom endpoint. An attacker can supply arbitrary commands through the fota_url field, triggering execution with root privileges on the device. This flaw allows full compromise of the router, exposing the network and potentially providing a foothold for further attacks.

Affected Systems

D-Link DWR‑M961 4G AC1200 LTE routers with hardware version C1 running firmware older than 1.1.5_C1_202607071108.

Risk and Exploitability

The CVSS score of 9.3 underscores a critical severity. Although EPSS data is not published, the lack of a KEV listing does not reduce the urgency. The flaw can be exercised remotely by sending a crafted request to the vulnerable web interface; no special authentication is required per the description, so attackers can obtain root privilege directly. The impact spans confidentiality, integrity, and availability of the device and the network it supports.

Generated by OpenCVE AI on August 8, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest firmware release that addresses the vulnerability on all affected DWR‑M961 units.
  • If a firmware upgrade cannot be performed immediately, block or disable access to the /boafrm/formLtefotaUpgradeFibocom URL via the router’s web configuration or an external firewall.
  • Limit management interface exposure by restricting inbound traffic to trusted IP ranges or VPN only, and consider applying a web application firewall to filter malicious request payloads.

Generated by OpenCVE AI on August 8, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Sat, 08 Aug 2026 17:30:00 +0000


Sat, 08 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
Title D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T17:17:08.758Z

Reserved: 2026-08-08T16:43:04.176Z

Link: CVE-2026-71945

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T18:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')