Description
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

D-Link DWR‑M961 routers expose a command injection flaw in the /boafrm/formNtp endpoint. By injecting payloads into the ntpServerIp1 parameter, an adversary can cause the router to execute arbitrary shell commands with root privileges. The weakness stems from improper validation of input and is catalogued as CWE‑78.

Affected Systems

The vulnerability affects D‑Link Corp. DWR‑M961 4G AC‑1200 LTE devices that run hardware version C1 with firmware versions earlier than 1.1.5_C1_202607071108. Devices with newer firmware are not impacted.

Risk and Exploitability

The CVSS vector delivers a score of 9.3, indicating a critical impact and the availability of remote execution without authentication. EPSS details are not disclosed, and the issue is not currently in CISA’s KEV catalog. An attacker reaching the formNtp interface can remotely execute commands with system privileges, potentially compromising all services on the device.

Generated by OpenCVE AI on August 8, 2026 at 18:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update that removes the vulnerable input handling for the /boafrm/formNtp interface. This patch is documented in the D‑Link support announcement SAP10512.
  • Restrict access to the /boafrm/formNtp endpoint by configuring the device’s firewall or placing the router behind a network segmentation boundary, limiting exposure to trusted administrative networks.
  • Monitor system logs for anomalous entries referencing unexpected NTP server values or repeated attempts to contact the formNtp path, and investigate any suspicious activity promptly.

Generated by OpenCVE AI on August 8, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Sat, 08 Aug 2026 17:30:00 +0000


Sat, 08 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
Title D-Link DWR-M961 Command Injection via /boafrm/formNtp
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T17:19:39.345Z

Reserved: 2026-08-08T16:43:04.177Z

Link: CVE-2026-71953

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T18:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')