Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-71949: D-Link DWR-M961 Devices: Malicious Commands via Web Interface

CVE-2026-71949 · published 27 days ago
Summary

D-Link DWR-M961 devices with outdated firmware are at risk of being hacked by an attacker who can inject malicious commands through the web interface. This can allow an attacker to take control of the device with full privileges. To protect your device, update the firmware to version 1.1.5_C1_202607071108 or later.

What to do
  • Update d-link corporation dwr-m961 to version 1.1.5_C1_202607071108 or later.
Affected software
VendorProductAffected versions
d-link corporation dwr-m961 < 1.1.5_C1_202607071108
Original advisory text
D-Link DWR-M961 Command Injection via /boafrm/formUSSDSetup
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published8 Aug 2026
Updated30 Aug 2026
First seen8 Aug 2026
Sources
CVE-2026-71949 · MITRE
Monitor software like this
Free during beta