Impact
A vulnerability allows command injection in the action_value field of /boafrm/formSmsManage on D‑Link DWR‑M961 routers. It permits a remote attacker to execute arbitrary commands with root privileges, creating full system compromise. This flaw violates confidentiality, integrity and availability, and represents a classic OS command injection (CWE‑78).
Affected Systems
Vendor D‑Link Corporation’s DWR‑M961 4G AC1200 LTE router series is affected. The flaw exists in hardware version C1 with firmware versions older than 1.1.5_C1_202607071108. Devices that run earlier builds and expose the web interface at /boafrm/formSmsManage are at risk.
Risk and Exploitability
The CVSS base score of 9.3 reflects a high likelihood of remote exploitation with full system compromise. The EPSS score is not available, but the absence of a KEV listing does not diminish the risk; the lack of a known public exploit does not guarantee safety. Based on the description, the likely attack vector is a remote web request to the device's HTTP interface, potentially without authentication. An attacker can send a crafted action_value payload that the router passes directly to a shell, executing the supplied commands with root privileges.
OpenCVE Enrichment