HomeSecurityD-Link DWR-M961: 18 vulnerabilities allow root commands

D-Link DWR-M961: 18 vulnerabilities allow root commands

The D-Link DWR-M961 is at the center of a new advisory, as the C1 version contains 18 vulnerabilities, some of which are critical, that could allow a remote attacker to execute commands with root privileges. Users should check their software version immediately.

The official announcement from D-Link, dated August 3, 2026, concerns the DWR-M961 with hardware revision C1 and software 1.1.2_C1_202602110044 or earlier. The findings fall into the command injection and buffer overflow categories, while the patched version is 1.1.5_C1_202607071108.

See also: TRENDnet TEW-821DAP: New CVE in old router

D-Link DWR-M961 critical vulnerabilities

What the vulnerabilities in the D-Link DWR-M961 reveal

The entries published on August 8 describe multiple entry points in the router interfaces. For example, CVE-2026-71954 and CVE-2026-71955 allow command injection in VPN and WPS functions, while CVE-2026-71956 and CVE-2026-71957 concern app.cgi and quicksetup.cgi.

In CVE-2026-71954, a remote attacker can inject commands into the tunnelid and sessionid fields of the formL2tpv3ConfigSetup interface. The CVE entry reports a CVSS score of 9.8 and execution as root. The same pattern is seen in other management paths, without requiring prior authentication.

Meanwhile, CVE-2026-71958, CVE-2026-71948, and CVE-2026-71947 describe memory overflows or command injection in diagnostic functions. The common picture is particularly serious: requests intended for diagnostic tasks or network configuration can be transformed into the execution of arbitrary commands in the router's operating system.

D-Link reports a total of 18 findings, but the public material does not provide a single CVE list for the entire report. The available listings show that several features of the same software accept parameters without sufficient control. For this reason, patching the version is a safer option than trying to disable individual features.

Exposure increases when the management interface is accessible from the Internet or when the router is used in a network with multiple devices. An attacker who gains control could modify settings, monitor traffic, or use the DWR-M961 as a launching point for attacks on internal computers.

The problem is not just about the confidentiality of settings. Changing DNS can direct users to fake pages, while modifying VPN or wireless parameters can disrupt services or open new access paths. That's why the device must be treated as a critical network element, not a mere peripheral.

D-Link DWR-M961 Software Update

See also: Zbtlink Routers: Backdoor opens root shell

Why the D-Link DWR-M961 needs an immediate upgrade

The device acts as a gateway to the local network, so a successful attack could give access to network settings, connected systems, and data passing through the router. When the code is executed as root, the attacker gains the highest level of privileges on the device and can change its behavior.

D-Link is marking the report as resolved and asking DWR-M961 owners to use the C1 hardware revision package exclusively. The company notes that this is a non-US product, so availability and support process may vary by country. The download must be done from the official support page.

Router vulnerability protection D-Link DWR-M961

Protection measures for router owners

Administrators must first confirm the hardware model and revision from the management interface. Then, version 1.1.5_C1_202607071108 or later must be installed, according to D-Link's instructions. A file for a different revision should not be used, as it may cause failure or leave the device unsupported.

The version should not be confirmed by the name of the downloaded file alone. After rebooting, the administrator needs to log back into the device and confirm that the full string 1.1.5_C1_202607071108 or later is displayed. This process reduces the risk of an old version remaining active.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Until the upgrade is complete, it is wise to disable remote management unless necessary and restrict access to the management environment from a trusted network. After installation, administrators should check DNS, VPN, and WPS settings for unrecognized changes and review logs for unusual connections.

See also: AryStinger: Botnet infects D-Link routers

The SecNews technical team recommends an immediate inspection of every D-Link DWR-M961 C1 in operation, especially in small business and home networks. If there is evidence of a breach, the upgrade should be accompanied by changing administrative passwords, rechecking settings, and isolating the device until the investigation is complete.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS