Description
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a command injection flaw in the /boafrm/formL2tpv3ConfigSetup interface of D-Link DWR-M961 routers. Attackers can supply arbitrary commands in the tunnelid and sessionid fields, causing the router to execute those commands with root privileges. This loss of control can lead to complete compromise of confidentiality, integrity and availability of the device and any networks it connects to.

Affected Systems

D-Link Corporation’s DWR‑M961 model, specifically hardware version C1 running firmware versions prior to 1.1.5_C1_202607071108. Devices with newer firmware are not affected.

Risk and Exploitability

The CVSS score of 9.3 indicates a severe vulnerability. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the nature of the flaw—remote command execution—suggests a high likelihood of exploitation if the device is reachable over the network. The attack vector is inferred to be the web-based configuration interface; the description does not explicitly state authentication requirements, but the typical exposure of such forms implies that an attacker needs to reach the local management interface, either by local network access or remote management enabled. Events that enable this endpoint are therefore high risk.

Generated by OpenCVE AI on August 8, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest firmware update for the DWR‑M961 (version 1.1.5_C1_202607071108 or newer) as detailed in D-Link’s support announcement SAP10512.
  • If an immediate firmware update is not feasible, block or disable remote access to the /boafrm/formL2tpv3ConfigSetup endpoint to prevent the injection vector from being reachable.
  • Continuously monitor device logs for unexpected command execution or repeated connection attempts, and maintain network segmentation to limit potential lateral movement.

Generated by OpenCVE AI on August 8, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Sat, 08 Aug 2026 17:30:00 +0000


Sat, 08 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
Title D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T17:19:57.596Z

Reserved: 2026-08-08T16:43:04.177Z

Link: CVE-2026-71954

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T18:30:03Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')