Impact
A command‑injection flaw exists in the /boafrm/formPingDiagnosticRun interface of D-Link DWR‑M961 routers. By supplying a crafted value in the host field, a remote attacker can cause the device to execute arbitrary shell commands with root privileges, providing full control over the device.
Affected Systems
All D-Link DWR‑M961 routers with hardware version C1 running firmware versions earlier than 1.1.5_C1_202607071108 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. Because the attack vector is remote over the network and no mitigation is available in the firmware, exploitation is likely in environments where the router is reachable. Despite no EPSS data, the lack of CISA KEV listing does not reduce the urgency; the flaw permits execution with root privileges.
OpenCVE Enrichment