A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 20 Feb 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Dlink
Dlink dwr-m961
Dlink dwr-m961 Firmware
CPEs cpe:2.3:h:dlink:dwr-m961:-:*:*:*:*:*:*:*
cpe:2.3:o:dlink:dwr-m961_firmware:1.1.47:*:*:*:*:*:*:*
Vendors & Products Dlink
Dlink dwr-m961
Dlink dwr-m961 Firmware

Mon, 02 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared D-link
D-link dwr-961
Vendors & Products D-link
D-link dwr-961

Thu, 29 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in D-Link DWR-M961 1.1.47. The affected element is an unknown function of the file /boafrm/formLtefotaUpgradeFibocom. Such manipulation of the argument fota_url leads to command injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
Title D-Link DWR-M961 formLtefotaUpgradeFibocom command injection
Weaknesses CWE-74
CWE-77
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-02-23T09:07:19.760Z

Reserved: 2026-01-29T14:40:54.343Z

Link: CVE-2026-1624

cve-icon Vulnrichment

Updated: 2026-01-30T14:38:15.452Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-29T22:15:53.913

Modified: 2026-02-20T15:47:52.977

Link: CVE-2026-1624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-01-30T08:42:33Z

Weaknesses