CVE-2026-71947: D-Link DWR-M961 Command Injection via /boafrm/formTracerouteDiagnosticRun
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5C1202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
D-Link DWR-M961to a version that resolves this vulnerability.Fixed in 1.1.5_C1_202607071108
Event History
Frequently Asked Questions
What is the severity of CVE-2026-71947?
CVE-2026-71947 has a critical severity rating of 9.8.
How do I fix CVE-2026-71947?
To fix CVE-2026-71947, update the D-Link DWR-M961 device firmware to version 1.1.5_C1_202607071108 or later.
What type of vulnerability is CVE-2026-71947?
CVE-2026-71947 is classified as an OS Command Injection vulnerability.
Which devices are affected by CVE-2026-71947?
CVE-2026-71947 affects D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108.
What can an attacker do with CVE-2026-71947?
An attacker exploiting CVE-2026-71947 can inject arbitrary malicious commands into the host and ipVer fields, potentially compromising the device.