Impact
D-Link DWR-M961 routers running firmware version prior to 1.1.5_C1_202607071108 and hardware version C1 expose a command injection flaw in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary commands into the host field, which are executed with root privileges on the device, creating a full system compromise potential. This weakness falls under CWE-78: Improper Neutralization of Special Elements used in an OS Command.
Affected Systems
All D-Link DWR-M961 routers that use hardware version C1 and have a firmware build older than 1.1.5_C1_202607071108 are impacted. The vulnerability is specific to that hardware variant and firmware range.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, indicating critical impact. No EPSS score is available, and the CVE is not listed in the CISA KEV catalog, but the high severity combined with root-level access means a remote attacker with network reach to the router’s administration interface can exploit the flaw with relative ease. Based on the description, the likely attack vector is remote access to the web‑interface endpoint; authentication is not required to reach the vulnerable form.
OpenCVE Enrichment