Description
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

D-Link DWR-M961 routers running firmware version prior to 1.1.5_C1_202607071108 and hardware version C1 expose a command injection flaw in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary commands into the host field, which are executed with root privileges on the device, creating a full system compromise potential. This weakness falls under CWE-78: Improper Neutralization of Special Elements used in an OS Command.

Affected Systems

All D-Link DWR-M961 routers that use hardware version C1 and have a firmware build older than 1.1.5_C1_202607071108 are impacted. The vulnerability is specific to that hardware variant and firmware range.

Risk and Exploitability

The vulnerability has a CVSS score of 9.3, indicating critical impact. No EPSS score is available, and the CVE is not listed in the CISA KEV catalog, but the high severity combined with root-level access means a remote attacker with network reach to the router’s administration interface can exploit the flaw with relative ease. Based on the description, the likely attack vector is remote access to the web‑interface endpoint; authentication is not required to reach the vulnerable form.

Generated by OpenCVE AI on August 8, 2026 at 18:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to version 1.1.5_C1_202607071108 or later, as provided by D‑Link’s official security advisory.
  • Restrict or disable remote management of the device so that only trusted IP ranges can reach the web interface.
  • Apply firewall rules or network segmentation to block inbound traffic to the /boafrm endpoint or to the router’s LAN interface, reducing exposure to the vulnerable interface.

Generated by OpenCVE AI on August 8, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Sat, 08 Aug 2026 17:30:00 +0000


Sat, 08 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
Title D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T17:18:09.203Z

Reserved: 2026-08-08T16:43:04.176Z

Link: CVE-2026-71948

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T18:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')