D-Link patches critical command-injection vulnerabilities in DWR-M961 4G/LTE router

D-Link has fixed 15 security flaws in its DWR-M961 4G/LTE router, including command-injection bugs that could enable remote code execution, urging users to update firmware and tighten security settings.

D-Link has disclosed and patched 15 vulnerabilities in its DWR-M961 4G/LTE router, affecting hardware revision C1 and a range of web management functions that could let an attacker run shell commands or trigger memory corruption. According to the company’s advisory SAP10512, the flaws were fixed in firmware version 1.1.5_C1_202607071108, which was published after the advisory was first issued on 3 August and updated on 10 August.

The issues affect non-US devices running firmware 1.1.2_C1_202602110044 and earlier. D-Link said the model was not sold or supported by D-Link Systems in the United States, although it may be deployed in other markets. The findings cover 18 separate issues grouped into 15 CVE entries, with most of them concentrated in CGI handlers exposed through the router’s browser-based administration interface.

The most serious problems involve command injection in diagnostic, configuration and firmware-update features. These include ping, traceroute and debug tools, along with modem firmware-over-the-air update handlers for Quectel and Fibocom components. Security write-ups from Hol and Vulners on CVE-2026-71948 and CVE-2026-71946 note that crafted requests to the diagnostic endpoints can lead to remote command execution and, in some cases, root-level control. SentinelOne and OffSec Radar also describe separate command-injection weaknesses in SMS management and firmware-update code, underlining how broadly the device’s admin functions were exposed.

D-Link also identified injection paths in USSD settings, SMS handling, IMEI configuration, SIM PIN management, NTP configuration, L2TPv3 setup and Wi-Fi Protected Setup. The advisory says the WPS handler was especially problematic because some input values were not neutralised properly, allowing shell expansion in certain command contexts. Another flaw affects the JSON-based app.cgi diagnostic interface, where attacker-controlled ping destination data could be processed without sufficient validation.

Alongside the command-injection bugs, D-Link fixed three buffer-overflow issues in app.cgi and quicksetup.cgi. The company is advising owners to confirm that their router is the C1 revision, install the corrected firmware from the proper regional support channel and verify the version through the administration interface. It also recommends limiting management access to trusted networks, disabling unnecessary remote administration and reviewing logs for unusual diagnostic, WPS, SMS or setup activity.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.