Description
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
Published: 2026-08-08
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The D-Link DWR-M961 router exposes a command injection flaw in its web service endpoint /boafrm/formWsc, allowing an attacker to inject arbitrary shell commands through the localPin, targetAPSsid, peerPin, and peerRptPin input fields. This flaw is a classic Operating System Command Injection (CWE‑78) and can be leveraged to execute any command with root privileges on the device. Consequently, an attacker could take full control of the router, including its configuration, network traffic, and embedded services.

Affected Systems

D‑Link Corporation DWR‑M961 devices, specifically the hardware version C1 and software version 1.1.2_C1_202602110044. These devices run the affected firmware and are vulnerable when the /boafrm/formWsc endpoint is reachable.

Risk and Exploitability

The vulnerability has a CVSS score of 9.3, indicating critical severity. No EPSS data is published, and the weakness is not listed in CISA’s KEV catalog. The likely attack vector is remote, accessed through the router’s web interface over HTTP/HTTPS, and can be performed from any network that can reach the management interface. Successful exploitation leads to uncontrolled root-level execution, allowing full compromise of the device and the network segment it serves.

Generated by OpenCVE AI on August 8, 2026 at 18:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the router firmware to the latest release from D‑Link that removes the vulnerability.
  • If an immediate firmware upgrade is not feasible, restrict management traffic by configuring firewall rules or a VPN to allow access to the router only from trusted IP addresses.
  • Disable WPS and restrict authenticated access to the router’s configuration interface, ensuring only authorized personnel can manage the device and reducing the attack surface.

Generated by OpenCVE AI on August 8, 2026 at 18:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-m961
Vendors & Products D-link
D-link dwr-m961

Sat, 08 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin field, resulting in command execution with root privileges. D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
References

Sat, 08 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin field, resulting in command execution with root privileges.
Title D-Link DWR-M961 Command Injection via /boafrm/formWsc
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-08T17:20:15.562Z

Reserved: 2026-08-08T16:43:04.177Z

Link: CVE-2026-71955

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T19:00:10Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')