D-Link DWR-M961 Command Injection Vulnerability in formLtefotaUpgradeFibocom Endpoint

Vulnerability

A command injection vulnerability has been identified in the D-Link DWR-M961 4G LTE router, specifically in firmware version 1.1.47. The issue arises in the '/boafrm/formLtefotaUpgradeFibocom' endpoint, where the 'fota_url' parameter is not properly sanitized before being passed to a system command wrapper. This flaw allows authenticated attackers to inject arbitrary shell commands, which are executed with root privileges on the device.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the router with root privileges.

Reproduction

To reproduce this vulnerability, an authenticated user must send a POST request to the '/boafrm/formLtefotaUpgradeFibocom' endpoint. The request must include a crafted 'fota_url' parameter that contains the command injection payload, such as a URL with appended shell commands. The router's firmware will execute the injected commands with root privileges.

Added: Jan 29, 2026, 10:30 PM
Updated: Jan 29, 2026, 10:30 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.1
remediation
0.0
relevance
2.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.