Impact
A command injection flaw exists in the /boafrm/formPinManageSetup interface of D-Link DWR‑M961 routers, allowing an attacker to inject arbitrary shell commands via the oldPIn field. When triggered, the commands execute with root privileges, providing full control over the device. This vulnerability could lead to complete compromise of the network segment the device protects and enable further lateral movement.
Affected Systems
Devices from D‑Link Corporation using the DWR‑M961 model with hardware version C1 and firmware prior to 1.1.5_C1_202607071108 are impacted. Subsequent firmware releases beyond this version are not affected.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity, and although the EPSS score is not available, the lack of a KEV listing does not diminish the potential impact. The likely attack vector is remote over the public network via HTTP requests to the vulnerable endpoint, inferred from the fact that the flaw is triggered by an external input field. Given the root‑level execution, exploitation would grant an attacker full administrative control over the device and the connected network.
OpenCVE Enrichment