Impact
The vulnerability is a command injection flaw in the D-Link DWR-M961 router’s /boafrm/formIMEISetup interface. An attacker can place arbitrary commands into the IMEI_value field, which is executed with root privileges. This grants a malicious actor full control of the device, allowing unrestricted configuration changes, data exfiltration, or the installation of persistent malware.
Affected Systems
D-Link DWR-M961 routers with hardware version C1 and firmware versions earlier than 1.1.5_C1_202607071108 are affected. The flaw resides in the web interface accessed over the network, and based on the description, it is inferred that authentication is not required to exploit the flaw.
Risk and Exploitability
The CVSS score of 9.3 classifies this as a critical vulnerability. Because the flaw is a remote command injection that results in root execution, it is highly exploitable and would lead to complete compromise of the device. Based on the description, it is inferred that no authentication is required to exploit the vulnerability. The EPSS score is not available, so the exact probability of exploitation is unknown, but the public advisory and lack of a KEV listing suggest that widespread attacks have not yet been documented. Nonetheless, the potential impact warrants urgent action.
OpenCVE Enrichment