Description
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability allows command injection in the action_value field of /boafrm/formSmsManage on D‑Link DWR‑M961 routers. It permits a remote attacker to execute arbitrary commands with root privileges, creating full system compromise. This flaw violates confidentiality, integrity and availability, and represents a classic OS command injection (CWE‑78).

Affected Systems

Vendor D‑Link Corporation’s DWR‑M961 4G AC1200 LTE router series is affected. The flaw exists in hardware version C1 with firmware versions older than 1.1.5_C1_202607071108. Devices that run earlier builds and expose the web interface at /boafrm/formSmsManage are at risk.

Risk and Exploitability

The CVSS base score of 9.3 reflects a high likelihood of remote exploitation with full system compromise. The EPSS score is not available, but the absence of a KEV listing does not diminish the risk; the lack of a known public exploit does not guarantee safety. Based on the description, the likely attack vector is a remote web request to the device's HTTP interface, potentially without authentication. An attacker can send a crafted action_value payload that the router passes directly to a shell, executing the supplied commands with root privileges.

Generated by OpenCVE AI on August 8, 2026 at 18:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to firmware 1.1.5_C1_202607071108 or newer, as distributed by D‑Link, to remove the injection path.
  • Restrict access to the router’s web administration and SMS‑management pages to trusted administrators, preferably over a secured network segment and with HTTPS.
  • Disable the SMS‑management feature if it is not required, or block the /boafrm/formSmsManage endpoint entirely via router ACLs or an external firewall.
  • Monitor the router for abnormal command execution or unexpected outbound traffic and ensure logging is enabled for administrative actions.

Generated by OpenCVE AI on August 8, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Sat, 08 Aug 2026 17:30:00 +0000


Sat, 08 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.
Title D-Link DWR-M961 Command Injection via /boafrm/formSmsManage
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T17:18:45.298Z

Reserved: 2026-08-08T16:43:04.177Z

Link: CVE-2026-71950

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T19:00:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')