External risk intelligence

D-Link DWR-M961 Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71952

This device is a 4G LTE router. Management interfaces on consumer and small-business routers are frequently exposed to the internet or reachable via the WAN side by design in many common deployment configurations, making the vulnerable setup interface highly accessible.

OS Command Injection

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical command injection vulnerability found in D-Link routers. The flaw allows unauthorized remote attackers to execute arbitrary commands on affected devices with full root privileges by manipulating a specific interface. The main concern is confirming relevance and exposure to understand potential impact.

  • Routers can be remotely commanded without authorization.
  • Critical flaw allows taking full control of devices.
  • Confirm device relevance and direct exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the device's web interface. This interface is exposed to the network, allowing unauthenticated remote access. By submitting malicious input to a specific field within the `formPinManageSetup` function, an attacker could execute arbitrary commands with full root privileges on the affected device.

  • No authentication required for access.
  • Inputting malicious data into `oldPIn` field.
  • Remote command execution with root privileges.

Live Threat

Current exploitation, exposure, and threat context

The D-Link DWR-M961 router's command injection vulnerability could allow an attacker to execute arbitrary commands with root privileges when supported by the advisory's conditions. This could potentially affect the device's overall functionality and security.

  • Router command execution with root privileges.
  • Remote attacker injects commands into a specific field.
  • Compromise of router functionality and security.

Operational Fix

Recommended remediation, mitigation, and detection steps

The D-Link DWR-M961 router's command injection vulnerability necessitates immediate attention from network and security teams, as well as system owners responsible for network edge devices. The first practical step is to identify all deployed DWR-M961 devices, ascertain their exposure to the internet or internal networks, and confirm their business criticality. Once identified and prioritized, owners should plan for remediation, which may involve vendor coordination or temporary risk reduction measures.

  • Network and Security Teams own resolution.
  • Verify external and internal reachability first.
  • Plan remediation or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961?

The D-Link DWR-M961 is a 4G LTE router designed to provide internet connectivity for home or small-business environments. It functions as a gateway, routing traffic between the cellular network and connected devices. As a network edge component, it often acts as the primary firewall and bridge for all data passing in and out of a local area network.

What does CVE-2026-71952 mean for security?

This vulnerability is classified as Improper Neutralization of Special Elements used in an OS Command, or CWE-78. In plain terms, the router fails to properly sanitize input before processing it. Because of this, an attacker can trick the system into running unauthorized operating system commands with root privileges—the highest level of administrative control on the device.

How is this command injection triggered?

An attacker triggers this by sending a specially crafted request to the router's web interface specifically targeting the oldPIn field within the /boafrm/formPinManageSetup function. The vulnerability does not require authentication, meaning the attacker does not need a username or password to reach this interface and execute the commands. Simply navigating to the interface is sufficient to attempt the injection.

Is my device at risk based on Halo Surface Signal?

Yes, if you use this router, risk is elevated. Halo Surface Signal identifies this as an external threat because the device is a 4G LTE router. Management interfaces on these devices are frequently exposed to the internet or reachable via the WAN side by design. If your router's management page is accessible from the public internet, it is a primary candidate for this attack.

What should I do if I have this router?

First, perform an inventory to locate all DWR-M961 units in your environment. Check if these devices are directly exposed to the internet or reachable from untrusted networks. Once identified, prioritize these for updates. Contact the vendor for the latest firmware to ensure your device is patched beyond version 1.1.5_C1_202607071108 and restrict administrative access to internal-only segments whenever possible.

References