D-LINK has addressed 15 critical vulnerabilities in its DWR-M961 router, primarily stemming from command injection and buffer overflow issues within the router's web management tools. The vulnerabilities impact firmware versions prior to 1.1.5_C1_202607071108, and no active exploits have been confirmed. Users are strongly advised to update their firmware to mitigate potential risks, as these flaws can compromise the admin interface, allowing unauthorized system commands and potential exposure to attacks.
The weaknesses affect both diagnostic and management functions, with specific commands being particularly vulnerable. D-Link emphasizes the importance of network security, attributing the discovery of these issues to security researchers. Updates are necessary for maintaining device security.