External risk intelligence

D-Link DWR-M961 Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71947

The vulnerability exists in a D-Link 4G LTE router, a device typically deployed as an internet-facing gateway. The affected diagnostic interface is part of the router's web management portal, which is often exposed to the network, and the vulnerability is reachable remotely.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in certain D-Link routers, specifically within a diagnostic interface. This flaw allows remote attackers to execute commands with full administrative control over the affected devices. The main concern is to confirm if any of these devices are in use and if they are exposed to potential threats.

  • Unrestricted command execution on network devices.
  • Confirms potential for high-impact remote compromise.
  • Verify device relevance and exposure immediately.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to the router's web interface. The exposed diagnostic tool allows for the injection of malicious commands through specific input fields, leading to the execution of arbitrary code with the highest level of system privileges.

  • Requires network access to the router.
  • Triggered by inputting commands into diagnostic fields.
  • Enables remote command execution as root.

Live Threat

Current exploitation, exposure, and threat context

The D-Link DWR-M961 router's diagnostic interface could allow a remote attacker to execute arbitrary commands with root privileges when supported by the advisory. This could affect the device's operational integrity and any data it processes or transmits.

  • Device command execution.
  • Unauthenticated remote access.
  • Compromised network gateway.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in D-Link routers is most likely to impact network infrastructure and security teams responsible for internet-facing devices. The first practical step is to identify all deployed instances of the affected router model, confirm their external reachability and business criticality, and then assign an accountable owner for remediation planning.

  • Network and security teams own this issue.
  • Verify external reachability and business criticality.
  • Plan remote access lockdown or vendor engagement.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961?

The D-Link DWR-M961 is a 4G LTE router that provides network connectivity, often serving as a primary gateway for local networks to access the internet. It is designed to manage traffic flow and diagnostic tasks through an integrated web-based management interface.

What does CVE-2026-71947 mean?

This vulnerability is classified as OS Command Injection (CWE-78). It means the router's software fails to properly sanitize input in its diagnostic tools, allowing an attacker to inject and execute their own system-level commands on the device with root-level authority.

How is this vulnerability triggered?

The flaw is triggered by sending a malicious request to the router's traceroute diagnostic interface, specifically targeting the host or ipVer fields. It is not triggered by normal router operations or general web traffic; it requires specifically manipulated input directed at that interface.

Is my device at risk?

Per Halo Surface Signal, this risk is relevant if your router is internet-facing, as the management portal can be accessed remotely. Devices isolated to internal-only networks face a significantly lower likelihood of remote compromise, but should still be assessed for unauthorized access points.

What is the first step to take?

Begin by auditing your network to identify all DWR-M961 units with hardware version C1. Check their current firmware versions against 1.1.5_C1_202607071108; if they are running older software, consult D-Link’s official support channels to schedule an update or restrict access to the web interface.

References