• Home Support Forums Security Advisories Shop     English | French
Security Announcement
Announcement > SAP10512
(Non-US) DWR-M961 H/W Rev. C1 / F/W v1.1.2_C1 Multiple Vulnerability Report
Publication ID: SAP10512
Resolved Status: Yes
Published on: 3 August 2026 8:31 GMT
Last updated on: 10 August 2026 9:06 GMT


Overview

On May 29, 2026, D-Link Systems, Inc. (US) received a security report concerning the DWR-M961, hardware revision C1, running firmware version 1.1.2_C1_202602110044. The DWR-M961 is a non-US product and was not sold or supported by D-Link Systems, Inc. in the United States.

The complete technical report documents 18 numbered vulnerability findings, including command-injection and buffer-overflow vulnerabilities in the device’s web-management CGI components. Several numbered findings contain multiple affected parameters, operating modes, or request variants. The findings have now been publicly disclosed under 15 CVE identifiers, grouped based on impacted function and vulnerability type.

The reported findings affect the following components:


- formLtefotaUpgradeQuectel
- formLtefotaUpgradeFibocom
- formPingDiagnosticRun
- formTracerouteDiagnosticRun
- formDebugDiagnosticRun
- formUSSDSetup
- formSmsManage
- formIMEISetup
- formPinManageSetup
- formNtp
- formL2tpv3ConfigSetup
- formWsc
- app.cgi
- quicksetup.cgi

After receiving the report, D-Link investigated the findings and developed updated firmware. The reported issues were addressed in firmware version 1.1.5_C1_202607071108. The remediation was subsequently verified as resolving the reported vulnerabilities.

D-Link takes network security and user privacy seriously. D-Link maintains product-management and security-response resources to investigate reported security issues and provide appropriate product updates.

Report Information

Security Researcher: Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University

Original Report Received: May 28, 2026 (UTC)
 Reported Product: DWR-M961
 Hardware Revision: C1
 Reported Firmware: 1.1.2_C1_202602110044
 Number of Numbered Findings: 18
 Number of Public CVE Identifiers: 15
 Vulnerability Classes: Command Injection and Buffer Overflow
 Resolution Status: Resolved

Counting note: The supplied technical report is explicitly numbered from (1) through (18). Some findings contain multiple sub-points or request variants. This announcement follows the numbering in the source report. The 18 numbered findings correspond to 15 CVE identifiers because related findings were grouped based on impacted function and vulnerability type. Findings 12–14 share CVE-2026-71955 for formWsc command injection, and Findings 17–18 share CVE-2026-71958 for quicksetup.cgi buffer overflow.

Reported Vulnerabilities

Finding 1 — Command Injection in Quectel FOTA Upgrade Handler

CVE: CVE-2026-71944

The researcher reported a command-injection vulnerability in the Quectel firmware-over-the-air upgrade handler.

URI: /boafrm/formLtefotaUpgradeQuectel
 Affected Field: fota_url
 Component: Web-management CGI / FOTA upgrade
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 2 — Command Injection in Fibocom FOTA Upgrade Handler

CVE: CVE-2026-71945

The researcher reported a command-injection vulnerability in the Fibocom firmware-over-the-air upgrade handler.

URI: /boafrm/formLtefotaUpgradeFibocom
 Affected Field: fota_url
 Component: Web-management CGI / FOTA upgrade
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 3 — Command Injection in Ping Diagnostic Handler

CVE: CVE-2026-71946

The researcher reported a command-injection vulnerability in the ping diagnostic function.

URI: /boafrm/formPingDiagnosticRun
 Affected Field: host
 Component: Web-management CGI / diagnostics
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 4 — Command Injection in Traceroute Diagnostic Handler

CVE: CVE-2026-71947

The researcher reported a command-injection vulnerability in the traceroute diagnostic function.

URI: /boafrm/formTracerouteDiagnosticRun
 Affected Fields: host, ipVer
 Component: Web-management CGI / diagnostics
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 5 — Command Injection in Debug Diagnostic Handler

CVE: CVE-2026-71948

The researcher reported a command-injection vulnerability in the debug diagnostic function.

URI: /boafrm/formDebugDiagnosticRun
 Affected Field: host
 Component: Web-management CGI / diagnostics
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 6 — Command Injection in USSD Setup Handler

CVE: CVE-2026-71949

The researcher reported command-injection behavior in the USSD setup function through two operating modes.

URI: /boafrm/formUSSDSetup
 Affected Fields and Sub-points:

ussdValue when ussdStatusInput=ussd

selectMenuValue when ussdStatusInput=menu

Component: Web-management CGI / USSD management
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 7 — Command Injection in SMS Management Handler

CVE: CVE-2026-71950

The researcher reported command-injection behavior in the SMS management function through two action paths.

URI: /boafrm/formSmsManage
 Affected Field: action_value
 Affected Action Sub-points:

action_id=delete

action_id=readMsg

Component: Web-management CGI / SMS management
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 8 — Command Injection in IMEI Setup Handler

CVE: CVE-2026-71951

The researcher reported command-injection behavior in the IMEI configuration function through two input variants.

URI: /boafrm/formIMEISetup
 Affected Field: IMEI_value
 Reported Sub-points:

Unquoted command-substitution input

Single-quoted command-substitution input

Component: Web-management CGI / modem configuration
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 9 — Command Injection in PIN Management Handler

CVE: CVE-2026-71952

The researcher reported a command-injection vulnerability in the SIM PIN-management function.

URI: /boafrm/formPinManageSetup
 Affected Field: oldPIn
 Affected Operation: modifyPin
 Component: Web-management CGI / SIM PIN management
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 10 — Command Injection in NTP Configuration Handler

CVE: CVE-2026-71953

The researcher reported a command-injection vulnerability involving the primary NTP-server configuration value.

URI: /boafrm/formNtp
 Affected Field: ntpServerIp1
 Component: Web-management CGI / time configuration
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 11 — Command Injection in L2TPv3 Configuration Handler

CVE: CVE-2026-71954

The researcher reported command-injection behavior involving stored L2TPv3 identifiers. The reported sequence required one request to store crafted values and a subsequent request that caused the stored values to be used in a system command.

URI: /boafrm/formL2tpv3ConfigSetup
 Affected Fields: tunnelid, sessionid
 Reported Sub-points:

Initial request stores the affected identifier values.

A subsequent configuration request causes the prior values to be retrieved and used.

Component: Web-management CGI / L2TPv3 configuration
 Vulnerability Type: Stored Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 12 — Command Injection Through WPS Local PIN

CVE: CVE-2026-71955

The researcher reported command-injection behavior through the local WPS PIN value in two WPS trigger modes.

URI: /boafrm/formWsc
 Affected Field: localPin
 Reported Sub-points:

triggerPIN=1

triggerRptPIN=1

Component: Web-management CGI / WPS configuration
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 13 — Command Injection Through WPS Target SSID

CVE: CVE-2026-71955

The researcher reported that the input-escaping logic applied to the target access-point SSID did not process the dollar-sign character, allowing shell expansion within a double-quoted command context.

URI: /boafrm/formWsc
 Affected Field: targetAPSsid
 Component: Web-management CGI / WPS configuration
 Vulnerability Type: Command Injection / Insufficient Input Neutralization
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 14 — Command Injection Through WPS Peer PIN Values

CVE: CVE-2026-71955

The researcher reported command-injection behavior through WPS peer PIN values in multiple request modes.

URI: /boafrm/formWsc
 Affected Fields: peerPin, peerRptPin
 Reported Sub-points:

setPIN=1 with peerPin

setRptPIN=1 with a single-quoted peerRptPin value

setRptPIN=1 with an unquoted peerRptPin value

Component: Web-management CGI / WPS configuration
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 15 — Command Injection in app.cgi

CVE: CVE-2026-71956

The researcher reported a command-injection vulnerability in the JSON-based diagnostic function within app.cgi.

URI: /app/app.cgi
 Affected Object Path: netDig.ping.dst
 Component: app.cgi
 Vulnerability Type: Command Injection
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 16 — Buffer Overflow in app.cgi

CVE: CVE-2026-71957

The researcher reported a buffer-overflow vulnerability in the access-control configuration logic within app.cgi.

URI: /app/app.cgi
 Affected Object Path: netAcc.addlist[].name
 Component: app.cgi
 Vulnerability Type: Buffer Overflow
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 17 — Buffer Overflow in quicksetup.cgi Test Handler

CVE: CVE-2026-71958

The researcher reported a buffer-overflow vulnerability in the test4 request-processing path of quicksetup.cgi.

URI: /quicksetup.cgi
 Affected Request Path: test4
 Component: quicksetup.cgi
 Vulnerability Type: Buffer Overflow
 Status: Resolved in firmware 1.1.5_C1_202607071108

Finding 18 — Buffer Overflow in quicksetup.cgi Setup Parameters

CVE: CVE-2026-71958

The researcher reported a separate buffer-overflow vulnerability in the setup-parameter processing logic of quicksetup.cgi.

URI: /quicksetup.cgi
 Affected Request Paths and Fields:

Wi-Fi setup through setWiFi, affecting ssid2

Administrator setup through Apply, affecting username

Component: quicksetup.cgi
 Vulnerability Type: Buffer Overflow
 Status: Resolved in firmware 1.1.5_C1_202607071108

CVE, CWE, and CVSS Information

The reported vulnerabilities have now been publicly disclosed under 15 CVE identifiers, as listed with the applicable findings above. The CVE assignments group related issues based on impacted function and vulnerability type.

CWE assignments and CVSS scores should only be added where supported by the applicable public CVE record or another authoritative disclosure.

Affected Models

Model Hardware Revision Affected Software Version Region Fixed Release Last Updated
DWR-M961 C1 1.1.2_C1_202602110044 or earlier applicable C1 firmware Non-US / Global markets where distributed 1.1.5_C1_202607071108 08/10/2026


Security Update for Your D-Link Device

Users with a DWR-M961 hardware revision C1 should install firmware version 1.1.5_C1_202607071108 or later.

Firmware download
:
 https://support.dlink.com/resource/SECURITY_ADVISEMENTS/DWR-M961/REVC/DWR-M961_1.1.5_C1_202607071108.zip 

After installing the firmware, verify that the device’s administration interface reports firmware version 1.1.5_C1_202607071108 or a later version.

The DWR-M961 is a non-US product. Product availability, support, and update procedures may vary by country or regional D-Link organization.

D-Link products may be produced in multiple hardware revisions. Firmware is specific to the applicable model and hardware revision.

Before installing the update:

Confirm that the product model is DWR-M961.

Confirm that the hardware revision is C1.

Download only the firmware designated for DWR-M961 hardware revision C1.

Follow the firmware-installation instructions provided for the applicable regional product.

The hardware revision is printed on the product label near the serial number and may also be displayed in the device’s web-based administration interface.

Acknowledgment

D-Link thanks Jincheng Wang (@winmt), Professor Le Yu of Nanjing University of Posts and Telecommunications, and Professor Xiapu Luo of The Hong Kong Polytechnic University for reporting these issues and supporting the coordinated resolution process.