External risk intelligence

D-Link DWR-M961 Command Injection Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71945

The vulnerability affects a 4G LTE router, which is an internet edge gateway device designed to connect local networks to the internet. As a customer premises equipment (CPE) router, these devices are commonly exposed to the public internet by design to facilitate remote management or external connectivity.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A command injection vulnerability has been identified in certain D-Link routers, specifically impacting the firmware's remote upgrade interface. This flaw allows unauthenticated remote attackers to execute arbitrary commands on the affected devices, potentially leading to a full compromise of the router's capabilities. The main concern is confirming relevance and exposure.

  • Attackers can run unauthorized commands remotely.
  • Affects internet-facing routers, a critical network component.
  • Confirm if your internet edge devices are impacted.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to a D-Link router exposed to the internet. This request targets the firmware upgrade interface, specifically the `fota_url` parameter. By injecting malicious commands into this field, an attacker could gain root-level control over the device.

  • Accessible over the internet.
  • Malicious command injection via `fota_url`.
  • Full device control with root privileges.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected D-Link routers. This is possible when the device is accessible over the internet and the attacker can interact with the vulnerable interface by providing a malicious input in the `fota_url` field.

  • Router command execution and system control.
  • Via a specially crafted network request.
  • Full compromise of the network gateway.

Operational Fix

Recommended remediation, mitigation, and detection steps

The critical command injection vulnerability in D-Link DWR-M961 routers necessitates a coordinated response. Infrastructure and network security teams are typically responsible for managing edge devices like these routers, which often connect directly to the internet. The initial step involves identifying all deployed DWR-M961 devices, assessing their exposure to the internet, determining their business criticality, and locating the accountable owner for remediation planning.

  • Infrastructure and security teams own this issue.
  • Verify internet-facing router exposure and criticality.
  • Plan coordinated firmware updates or replacements.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961?

The D-Link DWR-M961 is a 4G LTE router designed to serve as a network gateway. It provides internet connectivity to local devices by bridging them to a cellular data network. Because it acts as an edge device—often sitting directly between the public internet and a private local network—it is responsible for managing traffic and maintaining the secure boundary for connected systems.

How does this command injection vulnerability work?

This vulnerability, classified as CWE-78, allows an attacker to manipulate the router's operating system by supplying malicious input. In this case, the firmware's upgrade interface fails to properly sanitize data provided in a specific URL parameter. Because the system executes this input with root privileges, the attacker effectively bypasses normal security controls to run their own commands directly on the router's processor.

What triggers this vulnerability in CVE-2026-71945?

An attacker triggers the flaw by sending a specially crafted request to the router's firmware upgrade interface, specifically targeting the fota_url field. The vulnerability is triggered only when this interface is accessible to the attacker. It does not occur if the router is not reachable over the network or if the attacker cannot reach the specific upgrade interface via the device's web-based management services.

Why is this CVE considered relevant to my network?

According to Halo Surface Signal, this vulnerability is highly relevant because the DWR-M961 is a customer premises equipment router. These devices are frequently deployed at the internet edge, meaning they are often exposed to the public internet by design. If your router is reachable from the public web, it can be targeted by remote, unauthenticated attackers, making it a critical priority for assessment.

What steps should I take if I use this router?

First, identify all DWR-M961 units in your environment and confirm their firmware version. If you are running a version prior to 1.1.5_C1_202607071108, the device is affected. Your primary goal is to isolate internet-facing instances and coordinate with your network or infrastructure teams to apply the necessary firmware update provided by the manufacturer to close the command injection vector.

References