Impact
The vulnerability is a command injection flaw in the /boafrm/formL2tpv3ConfigSetup interface of D-Link DWR-M961 routers. Attackers can supply arbitrary commands in the tunnelid and sessionid fields, causing the router to execute those commands with root privileges. This loss of control can lead to complete compromise of confidentiality, integrity and availability of the device and any networks it connects to.
Affected Systems
D-Link Corporation’s DWR‑M961 model, specifically hardware version C1 running firmware versions prior to 1.1.5_C1_202607071108. Devices with newer firmware are not affected.
Risk and Exploitability
The CVSS score of 9.3 indicates a severe vulnerability. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the nature of the flaw—remote command execution—suggests a high likelihood of exploitation if the device is reachable over the network. The attack vector is inferred to be the web-based configuration interface; the description does not explicitly state authentication requirements, but the typical exposure of such forms implies that an attacker needs to reach the local management interface, either by local network access or remote management enabled. Events that enable this endpoint are therefore high risk.
OpenCVE Enrichment