Impact
The D-Link DWR-M961 router exposes a command injection flaw in its web service endpoint /boafrm/formWsc, allowing an attacker to inject arbitrary shell commands through the localPin, targetAPSsid, peerPin, and peerRptPin input fields. This flaw is a classic Operating System Command Injection (CWE‑78) and can be leveraged to execute any command with root privileges on the device. Consequently, an attacker could take full control of the router, including its configuration, network traffic, and embedded services.
Affected Systems
D‑Link Corporation DWR‑M961 devices, specifically the hardware version C1 and software version 1.1.2_C1_202602110044. These devices run the affected firmware and are vulnerable when the /boafrm/formWsc endpoint is reachable.
Risk and Exploitability
The vulnerability has a CVSS score of 9.3, indicating critical severity. No EPSS data is published, and the weakness is not listed in CISA’s KEV catalog. The likely attack vector is remote, accessed through the router’s web interface over HTTP/HTTPS, and can be performed from any network that can reach the management interface. Successful exploitation leads to uncontrolled root-level execution, allowing full compromise of the device and the network segment it serves.
OpenCVE Enrichment