D-Link has disclosed and patched 15 Common Vulnerabilities and Exposures (CVEs) affecting its DWR-M961 4G/LTE router, specifically hardware revision C1.
This follows the discovery of multiple command injection and buffer overflow vulnerabilities in the device’s web management components. These vulnerabilities affect non-US DWR-M961 devices running firmware versions 1.1.2_C1_202602110044 and earlier revisions.
D-Link DWR-M961 Router Flaw
On August 3, 2026, D-Link published advisory SAP10512 and updated it on August 10. The company confirmed that these vulnerabilities were resolved in firmware version 1.1.5_C1_202607071108.
It is important to note that this router was neither sold nor supported by D-Link Systems, Inc. in the United States. However, it may be used in other global markets.
The coordinated disclosure includes 18 distinct findings grouped into 15 CVE identifiers. The majority of these issues are command-injection vulnerabilities in CGI handlers exposed through the device’s web administration interface.
Affected functions include firmware over-the-air upgrade handlers for Quectel and Fibocom modems, as well as diagnostic tools such as ping, traceroute, and debug.
Other functionalities impacted include USSD configuration, SMS management, IMEI setup, SIM PIN controls, Network Time Protocol configuration, L2TPv3 settings, and Wi-Fi Protected Setup (WPS).
An attacker capable of sending crafted requests to an affected management interface could inject shell commands due to insufficiently sanitized parameters.
For example, CVE-2026-71946 affects the host field used in the ping diagnostic endpoint. At the same time, CVE-2026-71947 impacts both the host and ipVer parameters in the traceroute handler.
The firmware-over-the-air (FOTA)-related issues, tracked under CVE-2026-71944 and CVE-2026-71945, involve the fota_url field in the Quectel and Fibocom update handlers.
Given that these features manage modem firmware update sources, failures in input validation can create significant vulnerabilities for attackers who already have access to router administration functions.
D-Link has also highlighted several command-injection vectors within the formWsc WPS handler under CVE-2026-71955. The affected inputs include local PIN, peer PIN, peer repeater PIN, and target access-point SSID values.
Notably, the advisory indicates that escaping the target SSID did not neutralize dollar-sign characters, which could allow shell expansion in a double-quoted command context.
Another issue, CVE-2026-71956, impacts the JSON-based app.cgi diagnostic interface. The vulnerable object path is netDig.ping.dst, which means the application-side ping feature can process attacker-controlled destination values without sufficient validation.
Additionally, three buffer-overflow findings were addressed. CVE-2026-71957 affects the access-control configuration processing in app.cgi, specifically the netAcc.addlist[].name field.
CVE-2026-71958 includes two flaws in quicksetup.cgi: one in the test4 request path and another affecting Wi-Fi and administrator setup parameters, including ssid2 and username.
D-Link advises owners of the DWR-M961 to verify that their device is hardware revision C1 and to install firmware version 1.1.5_C1_202607071108 or later.
Administrators should download firmware only from the appropriate regional D-Link support channel for their device and confirm the installed version through the router’s administration interface.
Organizations should also restrict router management access to trusted networks, turn off unnecessary remote administration services, and review device logs for any unusual diagnostic, WPS, SMS, or setup requests.
These vulnerabilities were reported by Jincheng Wang, Professor Le Yu from Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo from The Hong Kong Polytechnic University.
CVE Table
| CVE ID | Vulnerable Endpoint / Component | Vulnerability Type |
|---|---|---|
| CVE-2026-71944 | /boafrm/formLtefotaUpgradeQuectel | Command injection |
| CVE-2026-71945 | /boafrm/formLtefotaUpgradeFibocom | Command injection |
| CVE-2026-71946 | /boafrm/formPingDiagnosticRun | Command injection |
| CVE-2026-71947 | /boafrm/formTracerouteDiagnosticRun | Command injection |
| CVE-2026-71948 | /boafrm/formDebugDiagnosticRun | Command injection |
| CVE-2026-71949 | /boafrm/formUSSDSetup | Command injection |
| CVE-2026-71950 | /boafrm/formSmsManage | Command injection |
| CVE-2026-71951 | /boafrm/formIMEISetup | Command injection |
| CVE-2026-71952 | /boafrm/formPinManageSetup | Command injection |
| CVE-2026-71953 | /boafrm/formNtp | Command injection |
| CVE-2026-71954 | /boafrm/formL2tpv3ConfigSetup | Stored command injection |
| CVE-2026-71955 | /boafrm/formWsc | Command injection / insufficient input neutralization |
| CVE-2026-71956 | /app/app.cgi | Command injection |
| CVE-2026-71957 | /app/app.cgi | Buffer overflow |
| CVE-2026-71958 | /quicksetup.cgi | Buffer overflow |
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world





