Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a command injection vulnerability affecting D-Link DWR-M961 devices. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges by manipulating specific input fields in the device's web interface. This could potentially lead to a compromise of the device and the network it serves.
- Attackers can run any command on affected devices.
- Routers often sit at network perimeters.
- Confirm relevance and exposure of affected devices.
Attack Path
How an attacker could exploit the issue
An attacker could reach the D-Link DWR-M961 router from the internet without any authentication. By sending specially crafted data to the /boafrm/USSDSetup interface, they could trick the device into running arbitrary commands with full administrative control. This could allow the attacker to completely compromise the router and potentially disrupt network operations or use it as a pivot point for further attacks.
- No authentication or special access needed.
- Submitting malicious data to specific fields.
- Full command execution with root privileges.
Live Threat
Current exploitation, exposure, and threat context
A command injection vulnerability in the D-Link DWR-M961 router's /boafrm/formUSSDSetup interface could allow remote attackers to execute arbitrary commands with root privileges. This exposure is possible when supported by the advisory when the device is configured in a way that exposes this interface to unauthenticated remote access.
- System data and commands at risk.
- Inject commands via specific fields.
- Root-level access could be gained.
Operational Fix
Recommended remediation, mitigation, and detection steps
The primary responsibility for addressing this vulnerability lies with the infrastructure or network teams managing the D-Link DWR-M961 devices. The first practical step is to identify all deployed instances of this router, assess their internet-facing exposure and business criticality, and then assign ownership to the relevant team for remediation planning.
- Infrastructure or network teams own this.
- Verify internet exposure and business criticality.
- Plan remediation based on identified risk.