Sceawere

Vulnerability Detail

CVE-2026-71948UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

D-Link DWR-M961 Command Injection

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
4h ago
Vendor
D-Link Corporation
Product
DWR-M961
Attack Type
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-08T17:16:48.127Z",
  "pubdate": "2026-08-08T17:16:48.127Z",
  "executiveSummary": "D-Link DWR-M961 devices running hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108 suffer from an authenticated or unauthenticated command injection vulnerability within the /boafrm/formDebugDiagnosticRun diagnostic interface.\nThe root cause stems from improper input sanitization of parameters supplied to the debugging diagnostic functionality, allowing malicious actors to inject arbitrary system commands directly into the underlying operating system shell via the host field.\nSuccessful exploitation grants remote attackers arbitrary command execution capabilities with root privileges over the affected router.\nThis introduces severe risk implications, including complete system compromise, unauthorized network access, interception of traffic, and potential utilization of the device as a pivot point inside the local area network.\nAttackers require network access to the administrative or diagnostic interfaces exposed by the device to deliver the payload.",
  "technicalDetails": "The vulnerability resides in the web management interface of D-Link DWR-M961 devices, specifically within the form handler processing diagnostic routines located at the file path /boafrm/formDebugDiagnosticRun.\nThe vulnerable component fails to properly validate, sanitize, or escape user-supplied input accepted through the host field prior to passing it to system execution functions or the underlying operating system shell.\nThe affected product versions include hardware version C1 combined with firmware versions prior to 1.1.5_C1_202607071108.\nThe attack flow proceeds as follows: an attacker crafts an HTTP request targeting the /boafrm/formDebugDiagnosticRun interface, appending shell metacharacters or command separators followed by arbitrary malicious commands into the host parameter.\nUpon receiving the request, the web server or underlying binary passes the unsanitized host field directly to the system shell for evaluation, executing the attacker-supplied payload.\nBecause the web server and its child processes typically run with elevated privileges on embedded networking equipment, the injected commands are executed with root privileges.\nNetwork exposure is inherent due to the web-based management interface accessibility, though exposure depends on whether the management interface is accessible from the WAN or restricted to the LAN.\nPost-exploitation impact includes full administrative control over the underlying Linux-based operating system, ability to modify firmware, alter firewall rules, capture sensitive configuration data, disable security controls, and execute persistent malware within the targeted environment."
}