Critical Command Injection Vulnerability in D-Link DWR-M961 Devices

Critical Command Injection Vulnerability in D-Link DWR-M961 Devices

First seen 9 Aug 2026, 06:49 UTC Feedlywww.incibe.esexploit-intel.comwww.thehackerwire.comnitter.net 92% similarity 74.0

Article Content

Browse articles
ThreatCluster

A critical command injection vulnerability, CVE-2026-71954, has been identified in D-Link DWR-M961 devices with hardware version C1 and firmware versions prior to 1.1.5_C1_202607071108. This vulnerability allows unauthenticated remote attackers to execute arbitrary commands with root privileges via the /boafrm/formL2tpv3ConfigSetup interface. The CVSS base score assigned to this vulnerability is 9.8, indicating a high level of severity. Currently, there is no public proof-of-concept or confirmed exploitation reported. Users are advised to upgrade their firmware to the latest version to mitigate the risk. If immediate patching is not feasible, restricting network access to the vulnerable interface is recommended. The vulnerability was published on August 8, 2026.

Key Points: • CVE-2026-71954 is a critical command injection vulnerability in D-Link DWR-M961 devices. • The vulnerability allows remote command execution with root privileges via specific fields. • Users must upgrade to firmware version 1.1.5_C1_202607071108 or later to mitigate risks.

ThreatCluster AI How this analysis works

Timeline

2026-08-08
CVE-2026-71954 published
D-Link disclosed a critical command injection vulnerability affecting DWR-M961 devices with specific firmware versions.
Feedly
2026-08-09
Vulnerability details reported
Exploit Intelligence and Feedly reported on the command injection vulnerability, emphasizing its severity and potential impact.
exploit-intel.com

Community

Browse all →