Impact
The vulnerability allows a remote attacker to inject arbitrary commands through the ussdValue and selectMenuValue parameters on the /boafrm/formUSSDSetup endpoint. This results in execution with root privileges, effectively permitting complete compromise of the device. The core weakness is unsanitized command input (CWE‑78).
Affected Systems
D‑Link DWR‑M961 routers that use hardware revision C1 and run firmware versions earlier than 1.1.5_C1_202607071108 are affected. Devices with newer firmware or different hardware revisions are not impacted.
Risk and Exploitability
The CVSS score of 9.3 signals critical severity. No EPSS value is available, so the realistic exploitation probability cannot be quantified, though the lack of a KEV listing indicates no confirmed field exploitation to date. The most likely attack vector is over the network via the web management interface, where a remote user can send crafted HTTP requests to the vulnerable endpoint, gaining root-level access.
OpenCVE Enrichment