Description
A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Problem types
Product status
Timeline
| 2026-01-29: | Advisory disclosed |
| 2026-01-29: | VulDB entry created |
| 2026-01-29: | VulDB entry last update |
Credits
hhsw34 (VulDB User)
References
vuldb.com/?id.343383 (VDB-343383 | D-Link DWR-M961 formLtefotaUpgradeFibocom command injection)
vuldb.com/?ctiid.343383 (VDB-343383 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.740770 (Submit #740770 | D-Link DWR-M961 V1.1.47 Command Injection)
github.com/QIU-DIE/CVE/issues/50
www.dlink.com/