Impact
The D-Link DWR‑M961 router contains a buffer overflow in the quicksetup.cgi interface. An attacker who can send HTTP requests to the device can supply overly long strings to the test4, ssid2, and username fields, causing the firmware to overwrite memory and execute arbitrary commands. This enables remote attackers to take full control of the router, exfiltrate data, or use it as a foothold for wider network attacks.
Affected Systems
Affected devices are D-Link DWR‑M961 routers with hardware version C1 and software version 1.1.2_C1_202602110044. No other versions are listed.
Risk and Exploitability
The CVSS score is 9.3, indicating critical severity. No EPSS score is available, so the exact exploitation probability cannot be quantified. The vulnerability is not in the CISA KEV catalog. Because the flaw is triggered by external HTTP requests, an attacker who can reach the device over the internet or an internal network can exploit it, making the attack vector remote.
OpenCVE Enrichment