Impact
D-Link DWR‑M961 routers expose a command injection flaw in the /boafrm/formNtp endpoint. By injecting payloads into the ntpServerIp1 parameter, an adversary can cause the router to execute arbitrary shell commands with root privileges. The weakness stems from improper validation of input and is catalogued as CWE‑78.
Affected Systems
The vulnerability affects D‑Link Corp. DWR‑M961 4G AC‑1200 LTE devices that run hardware version C1 with firmware versions earlier than 1.1.5_C1_202607071108. Devices with newer firmware are not impacted.
Risk and Exploitability
The CVSS vector delivers a score of 9.3, indicating a critical impact and the availability of remote execution without authentication. EPSS details are not disclosed, and the issue is not currently in CISA’s KEV catalog. An attacker reaching the formNtp interface can remotely execute commands with system privileges, potentially compromising all services on the device.
OpenCVE Enrichment