External risk intelligence

D-Link DWR-M961 Command Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-71955

The vulnerability affects a D-Link 4G LTE router, a device typically deployed as an internet-facing gateway or edge device. The identified interface is part of the web-based management functionality, which is commonly accessible over the network in standard residential or small office deployments.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical security flaw has been identified in certain D-Link routers, allowing remote attackers to execute commands with full administrative privileges by exploiting a web interface vulnerability. This issue could potentially allow unauthorized access and control over the affected network devices.

  • Flaw allows remote takeover of routers.
  • Affects internet-facing network gateways.
  • Confirm relevance and understand exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted requests to the affected device over the internet. The vulnerability lies within the /boafrm/formWsc interface, where an attacker can inject malicious commands into the localPin field. Successful exploitation allows the attacker to execute arbitrary commands with root privileges on the device.

  • No special access needed.
  • Input field on web interface.
  • Full device control.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands with root privileges on D-Link DWR-M961 devices when the affected interface is accessible. This could impact the device's intended service behavior and potentially expose system-level data.

  • Device system data at risk.
  • Exploited via network-accessible interface.
  • Unauthorized command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

To address this vulnerability, infrastructure and network teams responsible for edge devices and internet-facing network hardware should take the lead. The first practical step is to identify all deployed instances of the affected D-Link router, confirm their network reachability and criticality to business operations, and then identify the accountable owner for remediation planning.

  • Ownership: Infrastructure and network teams.
  • Verify first: Device location and network exposure.
  • Action: Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the D-Link DWR-M961?

The D-Link DWR-M961 is a 4G LTE router designed to provide wireless internet connectivity for homes and small offices. It acts as a gateway, managing network traffic between your local devices and the internet service provider's cellular network.

How does CVE-2026-71955 work?

This vulnerability is a command injection flaw, categorized as CWE-78. It means the router fails to properly sanitize input before processing it. By sending a specially crafted request to the router's web management interface, an attacker can trick the system into running unauthorized commands with root-level, or full administrative, system privileges.

Can any request trigger this vulnerability?

No. The flaw specifically resides in the /boafrm/formWsc interface, within the localPin field. Attacks occur only when malicious input is sent directly to this specific parameter. Requests that do not interact with the localPin field or those targeting different router services do not trigger this specific security weakness.

Why is this CVE concerning for my network?

Halo Surface Signal notes that this router is typically used as an internet-facing edge device. Because the vulnerable web interface is often accessible over the network, an attacker could potentially reach and exploit the router directly from the internet without needing prior access to your internal network or user credentials.

How should I respond to this threat?

Begin by auditing your network to identify all deployed DWR-M961 units. Confirm whether these devices are reachable over the internet and determine their role in your infrastructure. Once you have a complete inventory, work with the accountable network or infrastructure team to coordinate the necessary firmware updates to mitigate the risk.

References