Wednesday, August 19, 2026

D-Link DWR-M961 Router Hit by 15 Command Injection and Buffer Overflow Vulnerabilities

D-Link has disclosed and patched 15 Common Vulnerabilities and Exposures (CVEs) affecting its DWR-M961 4G/LTE router, specifically hardware revision C1.

This follows the discovery of multiple command injection and buffer overflow vulnerabilities in the device’s web management components. These vulnerabilities affect non-US DWR-M961 devices running firmware versions 1.1.2_C1_202602110044 and earlier revisions.

On August 3, 2026, D-Link published advisory SAP10512 and updated it on August 10. The company confirmed that these vulnerabilities were resolved in firmware version 1.1.5_C1_202607071108.

It is important to note that this router was neither sold nor supported by D-Link Systems, Inc. in the United States. However, it may be used in other global markets.

The coordinated disclosure includes 18 distinct findings grouped into 15 CVE identifiers. The majority of these issues are command-injection vulnerabilities in CGI handlers exposed through the device’s web administration interface.

Affected functions include firmware over-the-air upgrade handlers for Quectel and Fibocom modems, as well as diagnostic tools such as ping, traceroute, and debug.

Other functionalities impacted include USSD configuration, SMS management, IMEI setup, SIM PIN controls, Network Time Protocol configuration, L2TPv3 settings, and Wi-Fi Protected Setup (WPS).

An attacker capable of sending crafted requests to an affected management interface could inject shell commands due to insufficiently sanitized parameters.

For example, CVE-2026-71946 affects the host field used in the ping diagnostic endpoint. At the same time, CVE-2026-71947 impacts both the host and ipVer parameters in the traceroute handler.

The firmware-over-the-air (FOTA)-related issues, tracked under CVE-2026-71944 and CVE-2026-71945, involve the fota_url field in the Quectel and Fibocom update handlers.

Given that these features manage modem firmware update sources, failures in input validation can create significant vulnerabilities for attackers who already have access to router administration functions.

D-Link has also highlighted several command-injection vectors within the formWsc WPS handler under CVE-2026-71955. The affected inputs include local PIN, peer PIN, peer repeater PIN, and target access-point SSID values.

Notably, the advisory indicates that escaping the target SSID did not neutralize dollar-sign characters, which could allow shell expansion in a double-quoted command context.

Another issue, CVE-2026-71956, impacts the JSON-based app.cgi diagnostic interface. The vulnerable object path is netDig.ping.dst, which means the application-side ping feature can process attacker-controlled destination values without sufficient validation.

Additionally, three buffer-overflow findings were addressed. CVE-2026-71957 affects the access-control configuration processing in app.cgi, specifically the netAcc.addlist[].name field.

CVE-2026-71958 includes two flaws in quicksetup.cgi: one in the test4 request path and another affecting Wi-Fi and administrator setup parameters, including ssid2 and username.

D-Link advises owners of the DWR-M961 to verify that their device is hardware revision C1 and to install firmware version 1.1.5_C1_202607071108 or later.

Administrators should download firmware only from the appropriate regional D-Link support channel for their device and confirm the installed version through the router’s administration interface.

Organizations should also restrict router management access to trusted networks, turn off unnecessary remote administration services, and review device logs for any unusual diagnostic, WPS, SMS, or setup requests.

These vulnerabilities were reported by Jincheng Wang, Professor Le Yu from Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo from The Hong Kong Polytechnic University.

CVE Table

CVE IDVulnerable Endpoint / ComponentVulnerability Type
CVE-2026-71944/boafrm/formLtefotaUpgradeQuectelCommand injection
CVE-2026-71945/boafrm/formLtefotaUpgradeFibocomCommand injection
CVE-2026-71946/boafrm/formPingDiagnosticRunCommand injection
CVE-2026-71947/boafrm/formTracerouteDiagnosticRunCommand injection
CVE-2026-71948/boafrm/formDebugDiagnosticRunCommand injection
CVE-2026-71949/boafrm/formUSSDSetupCommand injection
CVE-2026-71950/boafrm/formSmsManageCommand injection
CVE-2026-71951/boafrm/formIMEISetupCommand injection
CVE-2026-71952/boafrm/formPinManageSetupCommand injection
CVE-2026-71953/boafrm/formNtpCommand injection
CVE-2026-71954/boafrm/formL2tpv3ConfigSetupStored command injection
CVE-2026-71955/boafrm/formWscCommand injection / insufficient input neutralization
CVE-2026-71956/app/app.cgiCommand injection
CVE-2026-71957/app/app.cgiBuffer overflow
CVE-2026-71958/quicksetup.cgiBuffer overflow

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Ransom Busters Ransomware Affiliate Targets Victims With Fake Data Recovery Extortion

A threat actor calling itself “Ransom Busters” is targeting...

RAVEN Tool Steals Entire Elasticsearch Databases and Rebuilds Deleted Backdoors

The RAVEN offensive framework can turn compromised Elasticsearch and...

Critical Apache HttpComponents Client Flaw Lets Attackers Impersonate Servers

A critical vulnerability in the Apache HttpComponents Client can...

CISA Warns Hackers Are Actively Exploiting VMware vCenter Path Traversal Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Fake Claude Install Guide Steals Mac Passwords and Turns Trusted Crypto Wallet Apps Into Phishing Traps

A Google-sponsored search result for Claude installation instructions is...

Hackers Abuse Thousands of WordPress Sites to Spread StopAndProtect Malware via ClickFix

A large-scale malware operation called StopAndProtect is exploiting thousands...

Cl0p Hackers Exploit PTC Windchill Vulnerability to Deploy Custom Web Shell and Steal Data

The Cl0p ransomware and extortion operation is likely exploiting...

Related Articles

Recent News