Sceawere

Vulnerability Detail

CVE-2026-71947UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

D-Link DWR-M961 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
D-Link Corporation
Product
DWR-M961
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-08T17:16:47.983Z",
  "pubdate": "2026-08-08T17:16:47.983Z",
  "executiveSummary": "D-Link DWR-M961 routers running hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 suffer from a critical command injection vulnerability. The flaw resides within the traceroute diagnostic web interface, specifically targeting the /boafrm/formTracerouteDiagnosticRun endpoint. Unauthenticated or remote attackers can leverage this vulnerability by supplying maliciously crafted input through specific parameters to execute arbitrary system commands directly on the underlying operating system. Because the affected web services typically operate with elevated system privileges, successful exploitation results in complete administrative compromise of the device. This allows malicious actors to execute arbitrary code with root privileges, potentially hijacking network traffic, establishing persistent access, pivoting into internal local area networks, or disrupting critical routing functions. Remediation requires updating the firmware to version 1.1.5_C1_202607071108 or later as provided by the vendor.",
  "technicalDetails": "The vulnerability is classified as an OS command injection flaw located within the /boafrm/formTracerouteDiagnosticRun interface of D-Link DWR-M961 devices running hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108. The root cause stems from improper input sanitization and validation within the web application backend. Specifically, user-supplied data transmitted via the host and ipVer fields is passed directly or concatenated unsafely into system shell execution routines without adequate filtering for shell metacharacters, control operators, or command separators.\nDuring a typical attack flow, a remote attacker crafts a specialized HTTP request targeting the vulnerable /boafrm/formTracerouteDiagnosticRun endpoint. By injecting malicious command sequences (such as pipe characters, semicolons, or backticks) combined with system utilities into the vulnerable host or ipVer parameters, the attacker forces the underlying binary or script to execute unintended operating system commands. Because the web server process and associated diagnostic handlers run with root privileges, the injected payload executes with the highest level of system authorization.\nThe attack vector is network-exposed, meaning any remote attacker with network access to the administrative web interface or vulnerable diagnostic utility can initiate the exploit. Depending on the device configuration and exposure, this can be exploited remotely over the WAN or locally via the LAN. The post-exploitation impact includes full system compromise, modification of system configurations, interception of data traversing the router, installation of backdoors, and total loss of device integrity."
}