ThreatCluster

Critical Vulnerabilities in D-Link DWR-M961 Routers Expose Users to Remote Attacks

First seen 10 Aug 2026, 05:34 UTC Ciberseguridadlatam 79% similarity 70

Article Content

Browse articles
ThreatCluster

D-Link's 4G routers, specifically the DWR-M961 model, have been found to contain multiple critical vulnerabilities allowing remote code execution without authentication. CVE-2026-71953 and CVE-2026-71952 permit attackers to execute arbitrary commands as root via NTP server field injection and PIN management field exploitation, respectively. Additionally, CVE-2026-71957 involves a buffer overflow in the web interface, enabling total device control. These vulnerabilities affect both corporate and home networks across Latin America. The National Vulnerability Database classified these issues as critical on August 10, 2026, prompting urgent advisories for users to secure their devices. D-Link has not yet released patches or updates to mitigate these vulnerabilities.

Key Points: • D-Link DWR-M961 routers have critical vulnerabilities allowing remote code execution. • CVE-2026-71953, CVE-2026-71952, and CVE-2026-71957 are the identified vulnerabilities. • Affected devices are widely used in both corporate and home networks across Latin America.

ThreatCluster AI How this analysis works

Timeline

2026-08-08
CVE-2026-71953 published
A vulnerability allowing remote command execution via NTP field injection was disclosed.
Ciberseguridadlatam
2026-08-08
CVE-2026-71952 published
A vulnerability enabling total control of the device through PIN management field exploitation was disclosed.
Ciberseguridadlatam
2026-08-08
CVE-2026-71957 published
A buffer overflow vulnerability in the web interface was disclosed, allowing device takeover.
Ciberseguridadlatam
2026-08-10
Vulnerabilities classified as critical
The National Vulnerability Database classified the vulnerabilities as critical, prompting urgent advisories.
Ciberseguridadlatam

Community

Browse all →