D-Link Dwr M961
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in D-Link Dwr M961.
By the Year
In 2026 there have been 15 vulnerabilities in D-Link Dwr M961 with an average score of 9.3 out of ten. Last year, in 2025 Dwr M961 had 1 security vulnerability published. That is, 14 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.50.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 15 | 9.30 |
| 2025 | 1 | 8.80 |
It may take a day or so for new Dwr M961 vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent D-Link Dwr M961 Security Vulnerabilities
D-Link DWR-M961 pre-1.1.5_C1 buffer overflow in QuickSetup.cgi
CVE-2026-71958
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Classic Buffer Overflow
D-Link DWR-M961 Buffer Overflow in app.cgi (v1.1.2_C1) - Remote Code Execution
CVE-2026-71957
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.
Classic Buffer Overflow
D-Link DWR-M961 Command Injection in app.cgi netDig.ping.dst (<=1.1.5_C1)
CVE-2026-71956
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.
Shell injection
D-Link DWR-M961 cmd injection in /boafrm/formWsc (1.1.5 C1)
CVE-2026-71955
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges.
Shell injection
Cmd Injection Root Priv in D-Link DWR-M961 <1.1.5_C1
CVE-2026-71954
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.
Shell injection
D-Link DWR-M961 C1: Root cmd injection via /boafrm/formNtp (before 1.1.5)
CVE-2026-71953
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.
Shell injection
D-Link DWR-M961 C1 firmware <1.1.5: cmd injection via formPinManageSetup root exec
CVE-2026-71952
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
Shell injection
Command Injection in D-Link DWR-M961 /boafrm/formIMEISetup (1.1.5)
CVE-2026-71951
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.
Shell injection
DWR-M961 Root Cmd Injection via /boafrm/formSmsManage field (v<1.1.5)
CVE-2026-71950
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.
Shell injection
D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup (pre 1.1.5_C1)
CVE-2026-71949
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
Shell injection
D-Link DWR-M961 <1.1.5_C1: cmd injection via /boafrm/formDebugDiagnosticRun
CVE-2026-71948
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
Shell injection
Command Injection in D-Link DWR-M961 (pre-1.1.5) exec formTracerouteDiagnosticRun
CVE-2026-71947
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges.
Shell injection
DWRM961 1.1.5C1 Firmware Command Injection via /boafrm/formPingDiagnosticRun
CVE-2026-71946
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.
Shell injection
D-Link DWR-M961 Command Injection via /boafrm/formLtefotaUpgradeFibocom (1.1.5)
CVE-2026-71945
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
Shell injection
D-Link DWR-M961 <1.1.5_C1 FOTA CmdInject RootExec
CVE-2026-71944
9.3 - Critical
- August 08, 2026
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges.
Shell injection
D-Link Router Buffer Overflow in /boafrm/formPingDiagnosticRun
CVE-2025-13304
8.8 - High
- November 17, 2025
A security flaw has been discovered in D-Link DWR-M920, DWR-M921, DWR-M960, DWR-M961 and DIR-825M 1.01.07/1.1.47. This vulnerability affects unknown code of the file /boafrm/formPingDiagnosticRun. Performing manipulation of the argument host results in buffer overflow. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
Classic Buffer Overflow
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for D-Link Dwr M961 or by D-Link? Click the Watch button to subscribe.