External risk intelligence

D-Link DWR-M961 Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71950

The vulnerability affects a 4G LTE router, which is a network edge device. The identified interface, related to SMS management, is part of the router's web-based management functionality. Such devices are designed to be internet-connected and often have management interfaces that are exposed or reachable, making them public-facing by design in many common deployment scenarios.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A command injection vulnerability has been identified in D-Link routers, specifically in the interface used for managing SMS messages. This flaw could allow an unauthorized remote attacker to execute arbitrary commands with root privileges on the affected devices, posing a significant security risk. The main concern is to confirm if our organization utilizes these specific D-Link devices and assess any potential exposure.

  • Flaw lets attackers run commands on routers.
  • Devices manage internet access and data.
  • Confirm relevance and check for exposure.

Attack Path

How an attacker could exploit the issue

An attacker with network access can target a D-Link router by sending specially crafted data to its web management interface. This data targets a feature used for managing SMS messages, where an input field can be manipulated to execute arbitrary commands on the device, leading to full control with root privileges.

  • No authentication or user interaction needed.
  • Malicious commands injected into SMS management.
  • Full device compromise with root privileges.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected D-Link routers, potentially impacting the device's normal operation and network connectivity.

  • Device’s command execution.
  • Remote command injection via SMS interface.
  • Compromise of device functionality.

Operational Fix

Recommended remediation, mitigation, and detection steps

The D-Link DWR-M961 router's command injection vulnerability likely impacts network infrastructure or IoT device management teams. The first practical step is to identify all deployed DWR-M961 devices, verify their internet reachability and business criticality, and then confirm the accountable owner for remediation planning.

  • Network and infrastructure teams own this.
  • Verify internet-reachable devices.
  • Plan vendor-assisted remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961?

The D-Link DWR-M961 is a 4G LTE router designed to provide wireless internet connectivity. It functions as a network gateway, often used in homes or small businesses to distribute data traffic. Beyond standard routing, this specific model includes management features that allow users to interact with SMS messaging directly through the device's administrative web interface.

What does command injection mean for CVE-2026-71950?

This vulnerability, classified as CWE-78 (OS Command Injection), occurs when a program fails to properly filter input. In CVE-2026-71950, the router's SMS management interface incorrectly processes user data. An attacker can use this flaw to slip malicious system-level commands into the router's operating system, which then executes them with the highest level of system permission, known as root privileges.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending specifically crafted network requests to the router's SMS management interface. The vulnerability resides in the 'action_value' field. Notably, this flaw does not require the attacker to have an existing account, nor does it require any interaction from a legitimate user; it can be triggered remotely as long as the interface is reachable.

Is my network at risk from CVE-2026-71950?

Halo Surface Signal notes that because the DWR-M961 is a network edge device, its web-based management interface is frequently exposed to the internet by design. If your router is configured to allow management access from the public-facing side of your network, it is inherently more reachable. Teams should verify if their units are exposed to these network paths.

How should I respond to this security flaw?

Begin by auditing your environment to identify all deployed DWR-M961 units. Once located, determine if they are internet-facing, as these represent the highest priority for protection. Coordinate with your network infrastructure teams to confirm the device version and prepare for vendor-supplied firmware updates, which are the standard mechanism to remediate this level of system flaw.

References