External risk intelligence

D-Link Router Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71949

This vulnerability affects a router, which is commonly deployed as an internet-facing gateway device. The affected interface handles network-related configurations, and such management surfaces on routers are often reachable from the internet or the network edge in standard deployment scenarios.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a command injection vulnerability affecting D-Link DWR-M961 devices. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges by manipulating specific input fields in the device's web interface. This could potentially lead to a compromise of the device and the network it serves.

  • Attackers can run any command on affected devices.
  • Routers often sit at network perimeters.
  • Confirm relevance and exposure of affected devices.

Attack Path

How an attacker could exploit the issue

An attacker could reach the D-Link DWR-M961 router from the internet without any authentication. By sending specially crafted data to the /boafrm/USSDSetup interface, they could trick the device into running arbitrary commands with full administrative control. This could allow the attacker to completely compromise the router and potentially disrupt network operations or use it as a pivot point for further attacks.

  • No authentication or special access needed.
  • Submitting malicious data to specific fields.
  • Full command execution with root privileges.

Live Threat

Current exploitation, exposure, and threat context

A command injection vulnerability in the D-Link DWR-M961 router's /boafrm/formUSSDSetup interface could allow remote attackers to execute arbitrary commands with root privileges. This exposure is possible when supported by the advisory when the device is configured in a way that exposes this interface to unauthenticated remote access.

  • System data and commands at risk.
  • Inject commands via specific fields.
  • Root-level access could be gained.

Operational Fix

Recommended remediation, mitigation, and detection steps

The primary responsibility for addressing this vulnerability lies with the infrastructure or network teams managing the D-Link DWR-M961 devices. The first practical step is to identify all deployed instances of this router, assess their internet-facing exposure and business criticality, and then assign ownership to the relevant team for remediation planning.

  • Infrastructure or network teams own this.
  • Verify internet exposure and business criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961?

The D-Link DWR-M961 is a 4G LTE router that provides high-speed wireless connectivity by serving as a bridge between cellular networks and local area networks. It is commonly deployed in homes or small offices as a gateway device to manage internet traffic, route data, and provide wireless access to connected devices.

How does CVE-2026-71949 create a security risk?

This vulnerability is classified as OS Command Injection (CWE-78). It means the router fails to properly sanitize input before processing it. By sending malicious commands through the specific USSD configuration fields, an attacker can trick the system into running those commands with root-level privileges, giving the attacker full administrative control over the device's operating system.

Do I need to be logged in to trigger this command injection?

No. The flaw exists in the device's public-facing management interface, meaning an attacker does not need an existing account or password to exploit it. The vulnerability is triggered solely by sending specially crafted data to the USSD setup interface; it is not triggered by standard, legitimate configuration changes or normal web traffic.

Is my DWR-M961 router at risk?

According to Halo Surface Signal, this vulnerability is particularly relevant if your router acts as an internet-facing gateway. Because the affected interface is part of the management surface, any DWR-M961 device reachable from the internet is at high risk of unauthorized access. Devices restricted to purely internal management are less likely to be directly reachable by external threats.

How do I start securing my affected devices?

The first step is to locate all instances of the DWR-M961 within your network environment. Once identified, evaluate whether these devices are exposed to the internet and determine their role in your business operations. After confirming your inventory and exposure, coordinate with your network or infrastructure team to apply the official firmware update provided by D-Link.

References