Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-71952: D-Link DWR-M961 Command Execution via Malicious Setup

CVE-2026-71952 · published 27 days ago
Summary

D-Link DWR-M961 devices with outdated firmware are at risk of being taken over by unauthorized users. This is because a malicious person can trick the device into executing commands with full access. Update your firmware to the latest version to prevent this risk.

What to do
  • Update d-link corporation dwr-m961 to version 1.1.5_C1_202607071108 or later.
Affected software
VendorProductAffected versions
d-link corporation dwr-m961 < 1.1.5_C1_202607071108
Original advisory text
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote at...
D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.
Severity
9.3 Critical
CVSS 3.1: 9.8 (MITRE)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published8 Aug 2026
Updated30 Aug 2026
First seen8 Aug 2026
Sources
CVE-2026-71952 · MITRE
Monitor software like this
Free during beta