External risk intelligence

D-Link DWR-M961 Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71951

The affected product is a wireless LTE router, a device designed to serve as an internet gateway. The vulnerable interface is part of the management surface typically accessible over the network, and such devices are commonly deployed at the network edge, making them directly reachable from the public internet by design.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts D-Link routers, specifically in how they handle certain network input. If exploited, an attacker could gain unauthorized control of the device, potentially affecting network operations. The primary concern is confirming if these devices are in use and, if so, understanding the extent of exposure.

  • Input handling flaw allows unauthorized control.
  • Could affect network access and operations.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted data to the device over the network. This data would target the IMEI setup interface, specifically the IMEI_value field. Successful injection into this field could allow an attacker to execute arbitrary commands on the device with root privileges.

  • No special access required.
  • Injecting data into IMEI field.
  • Root command execution possible.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected devices when the /boafrm/formIMEISetup interface is accessible. This could lead to a complete compromise of the device.

  • Affected asset: Router system.
  • Exposure: Network access to management interface.
  • Consequence: Full device compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

For D-Link DWR-M961 devices, infrastructure and network security teams are likely responsible for addressing this command injection vulnerability. The first practical step involves identifying all deployed DWR-M961 devices, confirming their network exposure and business criticality, and then locating the accountable owner for remediation planning.

  • Infrastructure teams should own the issue.
  • Verify device network exposure and criticality.
  • Plan coordinated firmware updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961?

The D-Link DWR-M961 is a 4G LTE wireless router designed to function as an internet gateway. These devices are typically used to provide network connectivity by bridging local wired or wireless traffic to cellular data networks, serving as a primary point of access for home or small office environments.

What does CVE-2026-71951 mean?

This CVE describes a command injection vulnerability, classified as CWE-78. It means the router fails to properly sanitize user input, allowing an attacker to insert unauthorized system commands. In this specific case, sending malicious data to the device can force it to run those commands with root privileges, giving an attacker full control over the system's core functions.

How is this command injection triggered?

An attacker triggers this flaw by sending specially crafted input specifically to the /boafrm/formIMEISetup interface, targeting the IMEI_value field. Simply interacting with other parts of the router's interface or sending standard network traffic does not activate this bug; it requires precise interaction with that specific management field.

Why is this router vulnerability a concern?

According to Halo Surface Signal, this router is designed as an internet gateway, meaning it is often placed at the edge of a network. Because the vulnerable management interface is typically reachable over the network, these devices are frequently exposed directly to the public internet, making them accessible to remote attackers without needing prior access to the internal network.

What should I do if I use this router?

Your first step is to identify all DWR-M961 units in your environment and determine if they are exposed to the internet. Once you have an inventory, coordinate with your infrastructure or network security team to verify the current firmware version and plan for an update to version 1.1.5_C1_202607071108 or later to resolve the vulnerability.

References