Impact
A command‑injection flaw exists in the /boafrm/formPingDiagnosticRun interface of D-Link DWR‑M961 routers. By supplying a crafted value in the host field, a remote attacker can cause the device to execute arbitrary shell commands with root privileges, providing full control over the device.
Affected Systems
All D-Link DWR‑M961 routers with hardware version C1 running firmware versions earlier than 1.1.5_C1_202607071108 are affected.
Risk and Exploitability
The vulnerability carries a CVSS score of 9.3, indicating critical severity. The EPSS score of 2%, while low, shows that some exploitation attempts are likely in networks where the router is reachable. Because the attack vector is remote over the network and no firmware mitigation is available, exploitation is likely in environments where the router is exposed. The lack of a CISA KEV listing does not reduce urgency, and the flaw permits execution with root privileges.
OpenCVE Enrichment