External risk intelligence

D-Link DWR-M961 Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71954

The affected product is a D-Link LTE router. Routers are commonly deployed as internet-facing gateway devices, and the vulnerable interface is part of the device configuration setup, which is frequently accessible over the network.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in certain D-Link routers, allowing unauthenticated remote attackers to execute arbitrary commands with full system privileges by manipulating specific configuration fields. This could potentially lead to unauthorized control or disruption of network devices. The main concern is confirming relevance and exposure.

  • Attackers can run any command on the router.
  • Routers are often internet-facing gateways.
  • Assess router relevance and network exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests over the network to the device's configuration interface. By manipulating the `tunnelid` and `sessionid` fields within the `/boafrm/formL2tpv3ConfigSetup` interface, an attacker could inject and execute arbitrary commands with root privileges.

  • No authentication or user interaction needed.
  • Inject commands into specific interface fields.
  • Remote code execution with root privileges.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on affected devices. This could occur when an attacker sends specially crafted requests to the `/boafrm/formL2tpv3ConfigSetup` interface.

  • Device configuration and control.
  • Unauthenticated network requests.
  • Complete system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

Infrastructure and network teams typically manage internet-facing devices like LTE routers. The first step is to locate all deployed D-Link DWR-M961 devices, determine their network accessibility, and identify the business criticality of each. Once accountable owners are identified, a prioritized remediation plan can be developed.

  • Infrastructure and network teams own.
  • Verify device reachability and business impact.
  • Plan remediation based on exposure risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961 and what is it used for?

The D-Link DWR-M961 is a 4G LTE router that provides internet connectivity. Users typically deploy these devices as gateway routers in homes or small offices to manage network traffic, bridge local devices to the internet, and handle cellular data connections.

What does command injection mean for CVE-2026-71954?

This vulnerability, classified as CWE-78, occurs when an application improperly filters user input before passing it to the underlying system shell. In this case, CVE-2026-71954 allows an attacker to insert malicious commands into specific configuration fields. Because the router processes these inputs without proper validation, the device executes the attacker's commands with root, or administrative, privileges.

How can an attacker trigger this vulnerability?

An attacker triggers this by sending a specially crafted request to the /boafrm/formL2tpv3ConfigSetup interface. They must target the tunnelid and sessionid fields to inject their commands. Importantly, this requires no prior authentication or user interaction; however, normal administrative configuration tasks performed through other, legitimate router menus do not trigger the bug.

Why should I care about this router vulnerability?

According to Halo Surface Signal, routers like the DWR-M961 are frequently deployed as internet-facing gateways, making them directly reachable from the public web. Because the vulnerability allows an unauthenticated remote attacker to gain root access, the device's high visibility and critical role in network management make it a significant security concern.

What is the first step to address this issue?

Begin by creating an inventory of all D-Link DWR-M961 devices within your network. Once identified, verify which units are reachable from the internet versus those strictly internal. Assess the business importance of these devices and coordinate with your infrastructure team to prioritize remediation for the most exposed or critical units.

References