Impact
D‑Link DWR‑M961 routers running hardware version C1 and firmware 1.1.2_C1_202602110044 are vulnerable to a command injection flaw in the app.cgi interface. An attacker can supply an arbitrary value for the netDig.ping.dst field, which is directly concatenated into a system command and executed with root privileges. This classic OS command injection (CWE‑78) lets an attacker run any command on the device, compromising confidentiality, integrity, and availability of the network. Based on the description, it is inferred that the attack vector is through HTTP requests to the publicly exposed web interface of the router, specifically targeting the app.cgi endpoint without authentication. The input is passed without proper sanitization, enabling the injection attack. The CVSS score of 9.3 indicates critical severity. The EPSS score is not available. As the flaw requires no authentication and relies on missing input validation on a publicly accessible endpoint, the exploitation likelihood is high in networks where the router is reachable. The vulnerability is not listed in CISA’s KEV catalog, so known exploits are not yet widely reported, but the potential for immediate attacks remains.
Affected Systems
D‑Link DWR‑M961 routers running hardware version C1 and firmware version 1.1.2_C1_202602110044.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. With no authentication required and the flaw residing on a publicly reachable web interface, the attack vector is likely HTTP requests to the app.cgi endpoint. The EPSS score is not available, but the lack of authentication and missing input validation suggest a high likelihood of exploitation in networks where the router is reachable. The vulnerability is not currently listed in CISA’s KEV catalog, so while no widespread exploits are reported, the potential for immediate remote attacks remains.
OpenCVE Enrichment